2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42645CRITICAL10CMSimple_XH 1.7.4 is affected by a remote code execution (RCE) vulnerability. To exploit this vulnerability, an attacker...
CVE-2021-42581CRITICAL9.1Prototype poisoning in function mapObjIndexed in Ramda 0.27.0 and earlier allows attackers to compromise integrity or av...
CVE-2021-41545HIGH7.5A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21....
CVE-2021-43712MEDIUM5.4Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker t...
CVE-2021-20479HIGH7.5IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could a...
CVE-2021-23792CRITICAL9.8The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injectio...
CVE-2021-23592CRITICAL9.8The package topthink/framework before 6.0.12 are vulnerable to Deserialization of Untrusted Data due to insecure unseria...
CVE-2021-27767HIGH7.8The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that c...
CVE-2021-27766HIGH7.8The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that co...
CVE-2021-27765HIGH7.8The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability tha...
CVE-2021-27764MEDIUM6.5Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie ...
CVE-2021-27762CRITICAL9.8Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web ...
CVE-2021-27761HIGH7.5Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks
CVE-2021-27760MEDIUM5.5An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime c...
CVE-2021-27759MEDIUM6.5This vulnerability arises because the application allows the user to perform some sensitive action without verifying tha...
CVE-2021-27758MEDIUM6.5There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after...
CVE-2021-27751LOW3.3HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session expires, in some circums...
CVE-2021-42743HIGH7.8A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Sp...
CVE-2021-36912MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress,...
CVE-2021-33845MEDIUM5.3The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The potential vulnerabilit...
CVE-2021-31559HIGH7.5A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexe...
CVE-2021-26253HIGH8.1A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in ...
CVE-2021-39027MEDIUM5IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 prepares a structured message for communication with another componen...
CVE-2021-39023HIGH7.5IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain sensitive information when a ...
CVE-2021-25746HIGH7.1A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadat...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now