2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40897HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting...
CVE-2021-40896HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted...
CVE-2021-40895HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted i...
CVE-2021-40894HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValue...
CVE-2021-42056MEDIUM6.7Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock ...
CVE-2021-40893HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-data v0.1.1 when validating craf...
CVE-2021-39409CRITICAL9.8A vulnerability exists in Online Student Rate System v1.0 that allows any user to register as an administrator without n...
CVE-2021-39408MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Online Student Rate System 1.0 via the page parameter on the index.ph...
CVE-2021-38879MEDIUM5.3IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information...
CVE-2021-38871MEDIUM5.4IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability all...
CVE-2021-29865MEDIUM5.4IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action o...
CVE-2021-20551LOW3.3IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 allows web pages to be stored locally which can be read by an...
CVE-2021-20544MEDIUM4.3IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may...
CVE-2021-20543MEDIUM5.4IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTML injection. A remote attacker could inje...
CVE-2021-20421MEDIUM4.3IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may...
CVE-2021-20355MEDIUM5.3IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information...
CVE-2021-39047MEDIUM6.1IBM Planning Analytics 2.0 and IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 are vulnerable to cross-site scripting. T...
CVE-2021-38945CRITICAL9.8IBM Cognos Analytics 11.2.1, 11.2.0, and 11.1.7 could allow a remote attacker to upload arbitrary files, caused by impro...
CVE-2021-29768MEDIUM6.5IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could allow a low level user to obtain sensitive information from the de...
CVE-2021-30651MEDIUM4.9A malicious authenticated SMG administrator user can obtain passwords for external LDAP/Active Directory servers that th...
CVE-2021-40892HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-color v2.1.0 when handling craft...
CVE-2021-41639MEDIUM5.5MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
CVE-2021-41638HIGH7.5The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to a...
CVE-2021-41637HIGH7.1Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configurati...
CVE-2021-41636MEDIUM6.5MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and op...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now