2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-46113HIGH8.8In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by ...
CVE-2021-45845HIGH7.8The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbi...
CVE-2021-45844HIGH7.8Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands...
CVE-2021-45803HIGH8.8MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is ...
CVE-2021-45342HIGH7.8A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker ...
CVE-2021-45341HIGH8.8A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker ...
CVE-2021-46483HIGH7.8Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.
CVE-2021-46482HIGH7.8Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.
CVE-2021-44988HIGH7.8Jerryscript v3.0.0 and below was discovered to contain a stack overflow via ecma_find_named_property in ecma-helpers.c.
CVE-2021-45222HIGH8.8An issue was discovered in COINS Construction Cloud 11.12. Due to logical flaws in the human ressources interface, it is...
CVE-2021-43588HIGH7.5Dell EMC Data Protection Central version 19.5 contains an Improper Input Validation Vulnerability. A remote unauthentica...
CVE-2021-4088HIGH7.2SQL injection vulnerability in Data Loss Protection (DLP) ePO extension 11.8.x prior to 11.8.100, 11.7.x prior to 11.7.1...
CVE-2021-44981HIGH8.8In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it int...
CVE-2021-25076HIGH8.8The WP User Frontend WordPress plugin before 3.5.26 does not validate and escape the status parameter before using it in...
CVE-2021-25073HIGH8.8The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example when deleting an ad, al...
CVE-2021-25045HIGH7.2The Asgaros Forum WordPress plugin before 1.15.15 does not validate or escape the forum_id parameter before using it in ...
CVE-2021-24936HIGH8The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its settings, nor sanitise an...
CVE-2021-24906HIGH7.5The Protect WP Admin WordPress plugin before 3.6.2 does not check for authorisation in the lib/pwa-deactivate.php file, ...
CVE-2021-24865HIGH7.2The Advanced Custom Fields: Extended WordPress plugin before 0.8.8.7 does not validate the order and orderby parameters ...
CVE-2021-24858HIGH7.2The Cookie Notification Plugin for WordPress plugin before 1.0.9 does not sanitise or escape the id GET parameter before...
CVE-2021-24696HIGH8.8The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to ...
CVE-2021-39293HIGH7.5In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many fil...
CVE-2021-39480HIGH7.5Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).
CVE-2021-46242HIGH8.8HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
CVE-2021-36339HIGH7.8The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentiall...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now