2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36826MEDIUM5.4Authenticated (subscriber or higher user role if allowed to access projects) Stored Cross-Site Scripting (XSS) vulnerabi...
CVE-2021-33010HIGH7.5An exception is thrown from a function in AVEVA System Platform versions 2017 through 2020 R2 P01, but it is not caught,...
CVE-2021-33008CRITICAL9.8AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for functionality that requi...
CVE-2021-32994HIGH7.5Softing OPC UA C++ SDK (Software Development Kit) versions from 5.59 to 5.64 exported library functions don't properly v...
CVE-2021-32986CRITICAL9.8After Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 is unlocked by an authorized user...
CVE-2021-32985HIGH7.2AVEVA System Platform versions 2017 through 2020 R2 P01 does not properly verify that the source of data or communicatio...
CVE-2021-32984CRITICAL9.8All programming connections receive the same unlocked privileges, which can result in a privilege escalation. During the...
CVE-2021-32982HIGH7.5Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 passwords are sent as plaintext during ...
CVE-2021-32981HIGH7.2AVEVA System Platform versions 2017 through 2020 R2 P01 uses external input to construct a pathname that is intended to ...
CVE-2021-32980CRITICAL9.8Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00 does not protect against additional sof...
CVE-2021-32978HIGH7.5The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previ...
CVE-2021-32977HIGH7.2AVEVA System Platform versions 2017 through 2020 R2 P01 does not verify, or incorrectly verifies, the cryptographic sign...
CVE-2021-43464HIGH8.8A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when th...
CVE-2021-43463HIGH7.8An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service execu...
CVE-2021-43462MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the username parameter.
CVE-2021-43461MEDIUM5.4Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the servername parameter.
CVE-2021-43460HIGH7.8An Unquoted Service Path vulnerability exists in System Explorer 7.0.0 via via a specially crafted file in the SystemExp...
CVE-2021-43459MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in Rumble Mail Server 0.51.3135 via the (1) domain and (2) path parame...
CVE-2021-25113MEDIUM5.4The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its sett...
CVE-2021-25048MEDIUM5.4The KingComposer WordPress plugin through 2.9.6 does not have authorisation, CSRF and sanitisation/escaping when creatin...
CVE-2021-43458HIGH7.8An Unquoted Service Path vulnerability exits in Vembu BDR 4.2.0.1 via a specially crafted file in the (1) hsflowd, (2) V...
CVE-2021-43457HIGH7.8An Unquoted Service Path vulnerability exists in bVPN 2.5.1 via a specially crafted file in the waselvpnserv service pat...
CVE-2021-43456HIGH7.8An Unquoted Service Path vulnerablility exists in Rumble Mail Server 0.51.3135 via via a specially crafted file in the R...
CVE-2021-43455HIGH7.8An Unquoted Service Path vulnerability exists in FreeLAN 2.2 via a specially crafted file in the FreeLAN Service path.
CVE-2021-43454HIGH7.8An Unquoted Service Path vulnerability exists in AnyTXT Searcher 1.2.394 via a specially crafted file in the ATService p...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now