2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36431CRITICAL9.1SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie informa...
CVE-2021-36426HIGH8.8File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to inc...
CVE-2021-36425MEDIUM5.4Directory traversal vulnerability in phpcms 1.9.25 allows remote attackers to delete arbitrary files via unfiltered $fil...
CVE-2021-36424CRITICAL9.8An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installatio...
CVE-2021-3809HIGH7.8Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi...
CVE-2021-3808HIGH7.8Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi...
CVE-2021-3439HIGH7.8HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being re...
CVE-2021-22786HIGH7.5A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on th...
CVE-2021-46873MEDIUM5.3WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be abl...
CVE-2021-4315HIGH8.8A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unkn...
CVE-2021-41231HIGH7.2OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to ...
CVE-2021-41144HIGH8.8OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the blo...
CVE-2021-41143HIGH7.2OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the cu...
CVE-2021-39217HIGH7.2OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to exec...
CVE-2021-21395MEDIUM4.3Magneto LTS (Long Term Support) is a community developed alternative to the Magento CE official releases. Versions prior...
CVE-2021-41989HIGH7.8Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2021-41988HIGH7.8Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2021-36686MEDIUM5.4Cross Site Scripting (XSS) vulnerability in yapi 1.9.1 allows attackers to execute arbitrary code via the /interface/api...
CVE-2021-36539MEDIUM6.5Instructure Canvas LMS didn't properly deny access to locked/unpublished files when the unprivileged user access the Doc...
CVE-2021-28510HIGH7.5For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invali...
CVE-2021-43449HIGH8.1ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor servic...
CVE-2021-43448MEDIUM5.3ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Improper Input Validation. A lack of input validation can allo...
CVE-2021-43447HIGH7.5ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the docume...
CVE-2021-43446MEDIUM6.1ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Cross Site Scripting (XSS). The "macros" feature of the docume...
CVE-2021-43445CRITICAL9.8ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now