2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-41158HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2021-37364HIGH7.8OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify perm...
CVE-2021-37363HIGH7.8An Insecure Permissions issue exists in Gestionale Open 11.00.00. A low privilege account is able to rename the mysqld.e...
CVE-2021-41078HIGH7.8Nameko through 2.13.0 can be tricked into performing arbitrary code execution when deserializing the config file.
CVE-2021-37372HIGH8.8Online Student Admission System 1.0 is affected by an insecure file upload vulnerability. A low privileged user can uplo...
CVE-2021-26609HIGH7.5A vulnerability was found in Mangboard(WordPress plugin). A SQL-Injection vulnerability was found in order_type paramete...
CVE-2021-40345HIGH7.2An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can uplo...
CVE-2021-40344HIGH7.2An issue was discovered in Nagios XI 5.8.5. In the Custom Includes section of the Admin panel, an administrator can uplo...
CVE-2021-40343HIGH7.8An issue was discovered in Nagios XI 5.8.5. Insecure file permissions on the nagios_unbundler.py file allow the nagios u...
CVE-2021-34595HIGH8.1A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 ...
CVE-2021-34593HIGH7.5In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid reque...
CVE-2021-34586HIGH7.5In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests may cause a Null pointer dereference in the ...
CVE-2021-34585HIGH7.5In the CODESYS V2 web server prior to V1.1.9.22 crafted web server requests can trigger a parser error. Since the parser...
CVE-2021-34583HIGH7.5Crafted web server requests may cause a heap-based buffer overflow and could therefore trigger a denial-of- service cond...
CVE-2021-41307HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to view the names of p...
CVE-2021-41306HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and ...
CVE-2021-41305HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view the names of private...
CVE-2021-41177HIGH8.1Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud...
CVE-2021-41145HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2021-41105HIGH7.5FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ...
CVE-2021-39225HIGH8.1Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2....
CVE-2021-38260HIGH7.8NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDe...
CVE-2021-38258HIGH7.8NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().
CVE-2021-34864HIGH8.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3 (...
CVE-2021-34863HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-2...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now