2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45476MEDIUM4.7Yordam Library Information Document Automation product before version 19.02 has an unauthenticated reflected XSS vulnera...
CVE-2021-45475MEDIUM5.3Yordam Library Information Document Automation product before version 19.02 has an unauthenticated Information disclosur...
CVE-2021-4228HIGH7.4Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the ...
CVE-2021-46850HIGH7.2myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An...
CVE-2021-46849Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29421. Reason: This candidate is a duplicate of ...
CVE-2021-46848CRITICAL9.1GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
CVE-2021-46279HIGH8.8Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attac...
CVE-2021-45925MEDIUM5.3Observable discrepancies in the login process allow an attacker to guess legitimate user names registered in the BMC. Th...
CVE-2021-44776MEDIUM5.3A broken access control vulnerability in the SubNet_handler_func function of spx_restservice allows an attacker to arbit...
CVE-2021-44769MEDIUM6.5An improper input validation vulnerability in the TLS certificate generation function allows an attacker to cause a Deni...
CVE-2021-44467HIGH7.5A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrari...
CVE-2021-42010CRITICAL9.8Heron versions <= 0.20.4-incubating allows CRLF log injection because of the lack of escaping in the log statements. Ple...
CVE-2021-26733HIGH7.5A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to a...
CVE-2021-26732MEDIUM5.3A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitr...
CVE-2021-26731CRITICAL9.8Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_rest...
CVE-2021-26730CRITICAL9.8A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allow...
CVE-2021-26729CRITICAL9.8Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_re...
CVE-2021-26728CRITICAL9.8Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice all...
CVE-2021-26727CRITICAL9.8Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_...
CVE-2021-42553CRITICAL9.8A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker t...
CVE-2021-33231MEDIUM5.4Cross Site Scripting (XSS) vulnerability in New equipment page in EasyVista Service Manager 2018.1.181.1 allows remote a...
CVE-2021-3305HIGH7.8Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.
CVE-2021-27406HIGH8.8An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any a...
CVE-2021-22685HIGH7.5An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controll...
CVE-2021-0699HIGH7.8In HTBLogKM of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now