2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36665HIGH7.8An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgr...
CVE-2021-44222CRITICAL9.1A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The underlying MQTT service o...
CVE-2021-44221HIGH7.5A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The affected systems do not p...
CVE-2021-41037HIGH8In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoin...
CVE-2021-41042MEDIUM5.3In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD l...
CVE-2021-35283CRITICAL9.8SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via...
CVE-2021-29281CRITICAL9.8File upload vulnerability in GFI Mail Archiver versions up to and including 15.1 via insecure implementation of Telerik ...
CVE-2021-44791MEDIUM6.1In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back i...
CVE-2021-31645HIGH7.5An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the conn...
CVE-2021-46825CRITICAL9.1Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauth...
CVE-2021-4234HIGH7.5OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset pac...
CVE-2021-3697HIGH7A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written...
CVE-2021-3696MEDIUM4.5A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data cor...
CVE-2021-3695MEDIUM4.5A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage ...
CVE-2021-37839MEDIUM4.3Apache Superset up to 1.5.1 allowed for authenticated users to access metadata information related to datasets they have...
CVE-2021-31679MEDIUM6.5An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that allows attackers to delete admin and other ...
CVE-2021-31678MEDIUM6.5An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can delete import information about a user'...
CVE-2021-31677MEDIUM6.5An issue was discovered in PESCMS-V2.3.3. There is a CSRF vulnerability that can modify admin and other members' passwor...
CVE-2021-31676MEDIUM6.1A reflected XSS was discovered in PESCMS-V2.3.3. When combined with CSRF in the same file, they can cause bigger destruc...
CVE-2021-46687MEDIUM4.9JFrog Artifactory prior to version 7.31.10 and 6.23.38 is vulnerable to Sensitive Data Exposure through the Project Admi...
CVE-2021-45721MEDIUM6.1JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one ...
CVE-2021-23163HIGH8.8JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific ...
CVE-2021-44915HIGH7.2Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.
CVE-2021-43116HIGH8.8An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on l...
CVE-2021-43702CRITICAL9ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitiz...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now