2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27279MEDIUM5.4MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).
CVE-2021-27564MEDIUM5.4A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups se...
CVE-2021-27549MEDIUM5.3Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor...
CVE-2021-27228CRITICAL9.8An issue was discovered in Shinobi through ocean version 1. lib/auth.js has Incorrect Access Control. Valid API Keys are...
CVE-2021-3120CRITICAL9.8An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allo...
CVE-2021-27559MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.
CVE-2021-27371MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
CVE-2021-27370MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
CVE-2021-27369MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
CVE-2021-27368MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.
CVE-2021-3149HIGH7.2On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authen...
CVE-2021-26120CRITICAL9.8Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
CVE-2021-26119HIGH7.5Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
CVE-2021-24115CRITICAL9.8In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, ba...
CVE-2021-27516HIGH7.5URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relati...
CVE-2021-27515MEDIUM5.3url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
CVE-2021-27514CRITICAL9.8EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-f...
CVE-2021-27513HIGH8.8The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files becau...
CVE-2021-26716MEDIUM6.1Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.
CVE-2021-26544MEDIUM5.4Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicio...
CVE-2021-3189MEDIUM6.1The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ ...
CVE-2021-27509HIGH7.5In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access c...
CVE-2021-26713MEDIUM6.5A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x bef...
CVE-2021-20588CRITICAL9.8Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Mo...
CVE-2021-20587CRITICAL9.8Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuratio...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now