2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-40334HIGH7.5Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 all...
CVE-2021-40333HIGH7.1Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access ...
CVE-2021-43795HIGH7.5Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local ...
CVE-2021-23263HIGH7.5Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and so...
CVE-2021-23262HIGH7.2Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.
CVE-2021-23259HIGH7.2Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib...
CVE-2021-23258HIGH7.2Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SP...
CVE-2021-44227HIGH8.8In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that tok...
CVE-2021-42711HIGH7.8Barracuda Network Access Client before 5.2.2 creates a Temporary File in a Directory with Insecure Permissions. This fil...
CVE-2021-43137HIGH8.8Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exits in hostel management system 2.1 via...
CVE-2021-41039HIGH7.5In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property proper...
CVE-2021-38575HIGH8.1NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
CVE-2021-42776HIGH7.7CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.
CVE-2021-20400HIGH7.5IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt h...
CVE-2021-44480HIGH8.1Wokka Lokka Q50 devices through 2021-11-30 allow remote attackers (who know the SIM phone number and password) to listen...
CVE-2021-20611HIGH7.5Improper Input Validation vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Series R04/0...
CVE-2021-20610HIGH7.5Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU...
CVE-2021-20609HIGH7.5Uncontrolled Resource Consumption vulnerability in Mitsubishi Electric MELSEC iQ-R Series R00/01/02CPU, MELSEC iQ-R Seri...
CVE-2021-32592HIGH7.8An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0,...
CVE-2021-4017HIGH8.8showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3984HIGH7.8vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-4019HIGH7.8vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-34599HIGH7.4Affected versions of CODESYS Git in Versions prior to V1.1.0.0 lack certificate validation in HTTPS handshakes. CODESYS ...
CVE-2021-20864HIGH8.8Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v...
CVE-2021-20863HIGH8OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.2...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now