2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31805CRITICAL9.8The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attribu...
CVE-2021-32040HIGH7.5It may be possible to have an extremely long aggregation pipeline in conjunction with a specific stage/operator and caus...
CVE-2021-42029HIGH7.8A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) V15 (All versions), SIMATIC STEP 7 (TIA Portal) V16 (...
CVE-2021-40368HIGH7.5A vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (...
CVE-2021-4047HIGH7.5The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was...
CVE-2021-46742CRITICAL9.1The multi-window module has a vulnerability of unauthorized insertion and tampering of Settings.Secure data.Successful e...
CVE-2021-46740HIGH7.5The device authentication service module has a defect vulnerability introduced in the design process.Successful exploita...
CVE-2021-43177MEDIUM5.3As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to re...
CVE-2021-40065HIGH7.5The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affec...
CVE-2021-38125CRITICAL9.8Unauthenticated remote code execution in Micro Focus Operations Bridge containerized, affecting versions 2021.05, 2021.0...
CVE-2021-36910MEDIUM4.8Authenticated (admin user role) Stored Cross-Site Scripting (XSS) in WP-Appbox (WordPress plugin) <= 4.3.20.
CVE-2021-36896MEDIUM4.8Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Pricing Table (WordPress p...
CVE-2021-36893MEDIUM4.8Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Responsive Tabs (WordPress...
CVE-2021-36848MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Feather (WordPress plugin) versio...
CVE-2021-36846MEDIUM4.8Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plu...
CVE-2021-22055MEDIUM5.3The SchedulerServer in Vmware photon allows remote attackers to inject logs through \r in the package parameter. Attacke...
CVE-2021-43442HIGH8.1A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 15110...
CVE-2021-39068MEDIUM5.4IBM Curam Social Program Management 8.0.1 and 7.0.11 is vulnerable to cross-site scripting. This vulnerability allows us...
CVE-2021-38930HIGH7.5IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remo...
CVE-2021-38929HIGH7.5IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remo...
CVE-2021-37293MEDIUM6.5A Directory Traversal vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 via the page...
CVE-2021-37292HIGH7.2An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocu...
CVE-2021-37291CRITICAL9.8An SQL Injection vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 ivia the input_id...
CVE-2021-40219HIGH8.8Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit ...
CVE-2021-34250Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2021-33396. Reason: This record is a duplicate of CVE-2021-...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now