2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25002HIGH7.5The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which co...
CVE-2021-32500Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-4200MEDIUM5.4A Improper Privilege Management vulnerability in SUSE Rancher allows write access to the Catalog for any user when restr...
CVE-2021-46790HIGH7.8ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream positi...
CVE-2021-36784HIGH7.2A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to...
CVE-2021-36778HIGH7.5A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather cred...
CVE-2021-40822HIGH7.5GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
CVE-2021-31674MEDIUM6.1Cyclos 4 PRO 4.14.7 and before does not validate user input at error inform, which allows remote unauthenticated attacke...
CVE-2021-31673MEDIUM6.1A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo...
CVE-2021-42001CRITICAL9.9PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposu...
CVE-2021-41994MEDIUM4.8A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to a...
CVE-2021-41993MEDIUM4.8A misconfiguration of RSA in PingID Android app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading ...
CVE-2021-41992MEDIUM5.6A misconfiguration of RSA in PingID Windows Login prior to 2.7 is vulnerable to pre-computed dictionary attacks, leading...
CVE-2021-4207HIGH8.2A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header....
CVE-2021-4206HIGH8.2A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lea...
CVE-2021-3982MEDIUM5.5Linux distributions using CAP_SYS_NICE for gnome-shell may be exposed to a privilege escalation issue. An attacker, with...
CVE-2021-36207HIGH8.8Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow ...
CVE-2021-43938CRITICAL9.8Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server witho...
CVE-2021-43937HIGH8.8Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, c...
CVE-2021-39082HIGH7.5IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to de...
CVE-2021-41948MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List ...
CVE-2021-44596CRITICAL9.8Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an ...
CVE-2021-44595HIGH8.8Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m...
CVE-2021-41942HIGH7.5The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sens...
CVE-2021-38952MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now