2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27279 | MEDIUM | 5.4 | 1.0% | Feb 22, 2021 | MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode). |
| CVE-2021-27564 | MEDIUM | 5.4 | 0.5% | Feb 22, 2021 | A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups se... |
| CVE-2021-27549 | MEDIUM | 5.3 | 1.1% | Feb 22, 2021 | Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor... |
| CVE-2021-27228 | CRITICAL | 9.8 | 1.6% | Feb 22, 2021 | An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are... |
| CVE-2021-3120 | CRITICAL | 9.8 | 36.8% | Feb 22, 2021 | An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allo... |
| CVE-2021-27559 | MEDIUM | 5.4 | 0.6% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field. |
| CVE-2021-27371 | MEDIUM | 5.4 | 0.6% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Description field. |
| CVE-2021-27370 | MEDIUM | 5.4 | 3.3% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field. |
| CVE-2021-27369 | MEDIUM | 5.4 | 0.6% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field. |
| CVE-2021-27368 | MEDIUM | 5.4 | 0.6% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the First Name field. |
| CVE-2021-3149 | HIGH | 7.2 | 4.4% | Feb 22, 2021 | On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authen... |
| CVE-2021-26120 | CRITICAL | 9.8 | 82.3% | Feb 22, 2021 | Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring. |
| CVE-2021-26119 | HIGH | 7.5 | 9.4% | Feb 22, 2021 | Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode. |
| CVE-2021-24115 | CRITICAL | 9.8 | 2.0% | Feb 22, 2021 | In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, ba... |
| CVE-2021-27516 | HIGH | 7.5 | 2.5% | Feb 22, 2021 | URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relati... |
| CVE-2021-27515 | MEDIUM | 5.3 | 2.0% | Feb 22, 2021 | url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. |
| CVE-2021-27514 | CRITICAL | 9.8 | 3.5% | Feb 22, 2021 | EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-f... |
| CVE-2021-27513 | HIGH | 8.8 | 28.4% | Feb 22, 2021 | The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files becau... |
| CVE-2021-26716 | MEDIUM | 6.1 | 0.8% | Feb 21, 2021 | Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter. |
| CVE-2021-26544 | MEDIUM | 5.4 | 2.8% | Feb 20, 2021 | Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicio... |
| CVE-2021-3189 | MEDIUM | 6.1 | 0.5% | Feb 19, 2021 | The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ ... |
| CVE-2021-27509 | HIGH | 7.5 | 1.0% | Feb 19, 2021 | In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access c... |
| CVE-2021-26713 | MEDIUM | 6.5 | 1.8% | Feb 19, 2021 | A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x bef... |
| CVE-2021-20588 | CRITICAL | 9.8 | 5.9% | Feb 19, 2021 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Mo... |
| CVE-2021-20587 | CRITICAL | 9.8 | 3.7% | Feb 19, 2021 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuratio... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now