2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34081HIGH8.8OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via ...
CVE-2021-34080CRITICAL9.8OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands v...
CVE-2021-34079CRITICAL9.8OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands ...
CVE-2021-34078HIGH8.8lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scan...
CVE-2021-33615HIGH7.5RSA Archer 6.8.00500.1003 P5 allows Unrestricted Upload of a File with a Dangerous Type.
CVE-2021-33504MEDIUM4.9Couchbase Server before 7.1.0 has Incorrect Access Control.
CVE-2021-33254HIGH7.5An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a d...
CVE-2021-32546HIGH8.8Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely...
CVE-2021-26635HIGH7.8In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target...
CVE-2021-26634CRITICAL9.8SQL injection and file upload attacks are possible due to insufficient validation of input values in some parameters and...
CVE-2021-26633CRITICAL9.8SQL injection and Local File Inclusion (LFI) vulnerabilities in MaxBoard can cause information leakage and privilege esc...
CVE-2021-27914MEDIUM4.8A cross-site scripting (XSS) vulnerability in the installer component of Mautic before 4.3.0 allows admins to inject exe...
CVE-2021-27778MEDIUM4.8HCL Traveler is vulnerable to a cross-site scripting (XSS) caused by improper validation of the Name parameter for Appro...
CVE-2021-3555HIGH8.8A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to ...
CVE-2021-27781MEDIUM4.8The Master operator may be able to embed script tag in HTML with alert pop-up display cookie.
CVE-2021-27780MEDIUM5.3The software may be vulnerable to both Un-Auth XML interaction and unauthenticated device enrollment.
CVE-2021-28509MEDIUM6.1This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent Te...
CVE-2021-28508MEDIUM6.1This advisory documents the impact of an internally found vulnerability in Arista EOS state streaming telemetry agent Te...
CVE-2021-4232MEDIUM6.1A vulnerability classified as problematic has been found in Zoo Management System 1.0. Affected is an unknown function o...
CVE-2021-33016CRITICAL9.8An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded credentials on KUKA KR C4 co...
CVE-2021-33014HIGH8.8An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versio...
CVE-2021-4231MEDIUM5.4A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the ...
CVE-2021-34360HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If explo...
CVE-2021-40317HIGH8.8Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.
CVE-2021-42860HIGH7.5A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it wil...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now