2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32927MEDIUM6.1An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS T...
CVE-2021-43708MEDIUM5.5The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification l...
CVE-2021-35229MEDIUM6.1Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when usi...
CVE-2021-23055MEDIUM6.5On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ing...
CVE-2021-41162MEDIUM6.1Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?opera...
CVE-2021-41161MEDIUM6.1Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't prope...
CVE-2021-43481CRITICAL9.8An SQL Injection vulnerability exists in Webtareas 2.4p3 and earlier via the $uq HTTP POST parameter in editapprovalstag...
CVE-2021-37740HIGH7.5A denial of service vulnerability exists in MDT's firmware for the KNXnet/IP Secure router SCN-IP100.03 and KNX IP inter...
CVE-2021-43990MEDIUM5.3The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload...
CVE-2021-43988MEDIUM5.9The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of fi...
CVE-2021-43986HIGH7The setup program for the affected product configures its files and folders with full access, which may allow unauthoriz...
CVE-2021-43933MEDIUM5.9The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receivin...
CVE-2021-38483MEDIUM5.7The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileg...
CVE-2021-3101HIGH8.8Hotdog, prior to v1.0.1, did not mimic the capabilities or the SELinux label of the target JVM process. This would allow...
CVE-2021-3100HIGH8.8The Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.1-13 didn’t mimic the permissions of the JVM be...
CVE-2021-4096HIGH8.8The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import cla...
CVE-2021-26627HIGH7.5Real-time image information exposure is caused by insufficient authentication for activated RTSP port. This vulnerabilit...
CVE-2021-26626HIGH8.8Improper input validation vulnerability in XPLATFORM's execBrowser method can cause execute arbitrary commands. IF the s...
CVE-2021-26625HIGH8.8Insufficient Verification of input Data leading to arbitrary file download and execute was discovered in Nexacro platfor...
CVE-2021-23283MEDIUM5.4Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerab...
CVE-2021-39078MEDIUM4.4IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM...
CVE-2021-39076HIGH7.5IBM Security Guardium 10.5 and 11.3 uses weaker than expected cryptographic algorithms that could allow an attacker to d...
CVE-2021-39072MEDIUM5.9IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to prope...
CVE-2021-39033MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote at...
CVE-2021-44519HIGH8.8In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Directory Traversal vulnerability, leading to re...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now