2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24009HIGH8.8Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of Fo...
CVE-2021-45104HIGH7.4An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor net...
CVE-2021-40375MEDIUM6.5Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having t...
CVE-2021-40374MEDIUM5.4A stored cross-site scripting (XSS) vulnerability was identified in Apperta Foundation OpenEyes 3.5.1. Updating a patien...
CVE-2021-30497HIGH7.5Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal...
CVE-2021-45103HIGH8.1An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S...
CVE-2021-41752CRITICAL9.8Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due t...
CVE-2021-41751CRITICAL9.8Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object...
CVE-2021-30080CRITICAL9.8An issue was discovered in the route lookup process in beego before 1.12.11 that allows attackers to bypass access contr...
CVE-2021-28428CRITICAL9.8File upload vulnerability in HorizontCMS before 1.0.0-beta.3 via uploading a .htaccess and *.hello files using the Media...
CVE-2021-27117HIGH7.8An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch ...
CVE-2021-27116HIGH7.8An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlin...
CVE-2021-41245HIGH8.1Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `...
CVE-2021-38834HIGH8.8easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through ...
CVE-2021-39114HIGH8.8Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data C...
CVE-2021-33207CRITICAL9.8The HTTP client in MashZone NextGen through 10.7 GA deserializes untrusted data when it gets an HTTP response with a 570...
CVE-2021-45893HIGH7.5An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case Sensitivity, which makes...
CVE-2021-45892MEDIUM5.9An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.
CVE-2021-45891HIGH8.8An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4., that allows attackers to escalate privileges within the ap...
CVE-2021-44109HIGH7.5A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a c...
CVE-2021-44108HIGH7.5A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of S...
CVE-2021-43008HIGH7.5Improper Access Control in Adminer versions 1.12.0 to 4.6.2 (fixed in version 4.6.3) allows an attacker to achieve Arbit...
CVE-2021-42324HIGH7.4An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470. Due to improper paramete...
CVE-2021-45894MEDIUM5.9An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Cleartext Transmission of Sensitive Information.
CVE-2021-36851MEDIUM5.4Authenticated (editor or higher user role) Cross-Site Scripting (XSS) vulnerability in Web-Settler Testimonial Slider – ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now