2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21946HIGH8.8Two heap-based buffer overflow vulnerabilities exists in the JPEG-JFIF lossless Huffman image parser functionality of Ac...
CVE-2021-21945HIGH8.8Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A spe...
CVE-2021-21944HIGH8.8Two heap-based buffer overflow vulnerabilities exist in the TIFF parser functionality of Accusoft ImageGear 19.10. A spe...
CVE-2021-21943HIGH8.8A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A special...
CVE-2021-21942HIGH8.8An out-of-bounds write vulnerability exists in the TIFF YCbCr image parser functionality of Accusoft ImageGear 19.10. A ...
CVE-2021-21939HIGH8.8A heap-based buffer overflow vulnerability exists in the XWD parser functionality of Accusoft ImageGear 19.10. A special...
CVE-2021-21938HIGH8.8A heap-based buffer overflow vulnerability exists in the Palette box parser functionality of Accusoft ImageGear 19.10. A...
CVE-2021-21914HIGH8.8A heap-based buffer overflow vulnerability exists in the DecoderStream::Append functionality of Accusoft ImageGear 19.10...
CVE-2021-45228MEDIUM5.4An XSS issue was discovered in COINS Construction Cloud 11.12. Due to insufficient neutralization of user input in the d...
CVE-2021-45227MEDIUM5.4An issue was discovered in COINS Construction Cloud 11.12. Due to an inappropriate use of HTML IFRAME elements, the file...
CVE-2021-43633MEDIUM5.4Sourcecodester Messaging Web Application 1.0 is vulnerable to stored XSS. If a sender inserts valid scripts into the cha...
CVE-2021-43290CRITICAL9.8An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a ma...
CVE-2021-43289HIGH7.5An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker who has compromised a GoCD agent can upload a ma...
CVE-2021-43288MEDIUM5.4An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker in control of a GoCD Agent can plant malicious J...
CVE-2021-43286HIGH8.8An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a Go...
CVE-2021-43287HIGH7.5An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default,...
CVE-2021-43154MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action i...
CVE-2021-41119HIGH7.5Wire-server is the system server for the wire back-end services. Releases prior to v2022-03-01 are subject to a denial o...
CVE-2021-42136CRITICAL9A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows...
CVE-2021-22797HIGH7.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal) vulnerability exists that could ...
CVE-2021-22795CRITICAL9.8A CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists...
CVE-2021-22794CRITICAL9.8A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could ...
CVE-2021-46167HIGH7.8An access control issue in the authentication module of wizplat PD065 v1.19 allows attackers to access sensitive data an...
CVE-2021-43741CRITICAL9.8CMSimple 5.4 is vulnerable to Directory Traversal. The vulnerability exists when a user changes the file name to malicio...
CVE-2021-43742MEDIUM5.4CMSimple 5.4 is vulnerable to Cross Site Scripting (XSS) via the file upload feature.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now