2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38944MEDIUM6.1IBM DataPower Gateway 10.0.2.0 through 1.0.3.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 is vulnera...
CVE-2021-42704HIGH7.8Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.
CVE-2021-42702LOW3.3Inkscape version 0.91 can access an uninitialized pointer, which may allow an attacker to have access to unauthorized in...
CVE-2021-42700LOW3.3Inkscape 0.91 is vulnerable to an out-of-bounds read, which may allow an attacker to have access to unauthorized informa...
CVE-2021-42852HIGH8A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authent...
CVE-2021-42851MEDIUM5.3A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to c...
CVE-2021-42850HIGH7.8A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud S...
CVE-2021-42849MEDIUM6.8A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow ...
CVE-2021-42848MEDIUM5.3An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an u...
CVE-2021-3969HIGH7A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System I...
CVE-2021-3956MEDIUM5.3A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Contro...
CVE-2021-3922HIGH7A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation,...
CVE-2021-27548MEDIUM5.5There is a Null Pointer Dereference vulnerability in the XFAScanner::scanNode() function in XFAScanner.cc in xpdf 4.03.
CVE-2021-41946MEDIUM5.4In FiberHome VDSL2 Modem HG150-Ub_V3.0, a stored cross-site scripting (XSS) vulnerability in Parental Control --> Access...
CVE-2021-35249MEDIUM4.3This broken access control vulnerability pertains specifically to a domain admin who can access configuration & user dat...
CVE-2021-38872HIGH7.5IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a re...
CVE-2021-29726MEDIUM5.3IBM Sterling Secure Proxy 6.0.3 and IBM Secure External Authentication Server 6.0.3 does not properly ensure that a cert...
CVE-2021-42644MEDIUM6.5cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file informa...
CVE-2021-42643HIGH8.8cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script f...
CVE-2021-42943MEDIUM5.4Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrar...
CVE-2021-33025HIGH7.8xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.
CVE-2021-33021MEDIUM6.1xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisa...
CVE-2021-33001MEDIUM6.1xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisv...
CVE-2021-27446CRITICAL9.8The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to exec...
CVE-2021-27444CRITICAL9.8The Weintek cMT product line is vulnerable to various improper access controls, which may allow an unauthenticated attac...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now