Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2021-3603 | PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the default, defined by PHPMailer::$validator), and the global namespace contains a function called php, it will be called in preference to the built-in validator of the same name. Mitigated in PHPMailer 6.5.0 by denying the use of simple strings as validato | 8.1 | 2.26% | 2021-06-17 | 2026-06-17 |
| CVE-2021-3645 | merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | 9.8 | 1.38% | 2021-09-10 | 2026-06-17 |
| CVE-2021-3666 | body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | 9.8 | 1.26% | 2021-09-13 | 2026-06-17 |
| CVE-2021-3693 | LedgerSMB does not check the origin of HTML fragments merged into the browser's DOM. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure. | 8.8 | 3.01% | 2021-08-23 | 2026-06-17 |
| CVE-2021-3694 | LedgerSMB does not sufficiently HTML-encode error messages sent to the browser. By sending a specially crafted URL to an authenticated user, this flaw can be abused for remote code execution and information disclosure. | 8.2 | 2.39% | 2021-08-23 | 2026-06-17 |
| CVE-2021-3734 | yourls is vulnerable to Improper Restriction of Rendered UI Layers or Frames | 8.8 | 0.39% | 2021-08-26 | 2026-06-17 |
| CVE-2021-3742 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in chatwoot/chatwoot, affecting all versions prior to 2.5.0. The vulnerability allows an attacker to upload an SVG file containing a malicious SSRF payload. When the SVG file is used as an avatar and opened in a new tab, it can trigger the SSRF, potentially leading to host redirection. | 8.8 | 0.37% | 2024-11-15 | 2026-06-17 |
| CVE-2021-3751 | libmobi is vulnerable to Out-of-bounds Write | 9.8 | 1.20% | 2021-09-15 | 2026-06-17 |
| CVE-2021-3756 | libmysofa is vulnerable to Heap-based Buffer Overflow | 9.8 | 1.03% | 2021-10-29 | 2026-06-17 |
| CVE-2021-3757 | immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | 9.8 | 1.65% | 2021-09-02 | 2026-06-17 |
| CVE-2021-3766 | objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | 9.8 | 1.47% | 2021-09-06 | 2026-06-17 |
| CVE-2021-3797 | hestiacp is vulnerable to Use of Wrong Operator in String Comparison | 9.8 | 1.11% | 2021-09-15 | 2026-06-17 |
| CVE-2021-3815 | utils.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | 9.8 | 0.84% | 2021-12-08 | 2026-06-17 |
| CVE-2021-3817 | wbce_cms is vulnerable to Improper Neutralization of Special Elements used in an SQL Command | 9.8 | 37.82% | 2021-12-09 | 2026-06-17 |
| CVE-2021-3819 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | 8.8 | 0.52% | 2021-09-27 | 2026-06-17 |
| CVE-2021-3838 | DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passing it into the file_get_contents() function. An attacker who can upload files of any type to the server can pass in the phar:// protocol to unserialize the uploaded file and instantiate arbitrary PHP objects. This can lead to remote code execution, especially when DOMPdf is used with frameworks with documented POP chains like Laravel or vulnerable developer code. | 9.8 | 1.43% | 2024-11-15 | 2026-06-17 |
| CVE-2021-3846 | firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type | 8.8 | 0.75% | 2021-10-19 | 2026-06-17 |
| CVE-2021-3850 | Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21. | 9.1 | 2.17% | 2022-01-25 | 2026-06-17 |
| CVE-2021-3858 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) | 8.8 | 0.53% | 2021-10-19 | 2026-06-17 |
| CVE-2021-3878 | corenlp is vulnerable to Improper Restriction of XML External Entity Reference | 9.8 | 1.83% | 2021-10-15 | 2026-06-17 |