2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-3872HIGH7.8vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3869HIGH7.5corenlp is vulnerable to Improper Restriction of XML External Entity Reference
CVE-2021-3858HIGH8.8snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3846HIGH8.8firefly-iii is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2021-38486HIGH8.5InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 cloud portal allows for self-registration of the aff...
CVE-2021-38484HIGH7.2InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not have a filter or signature check to detect or...
CVE-2021-38480HIGH8.8InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when un...
CVE-2021-38464HIGH7.4InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have inadequate encryption strength, which may allow...
CVE-2021-42261HIGH7.5Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation coul...
CVE-2021-36512HIGH7.5An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers t...
CVE-2021-41155HIGH8.8Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi...
CVE-2021-41154HIGH8.8Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi...
CVE-2021-41152HIGH7.7OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning man...
CVE-2021-36513HIGH7.5An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may all...
CVE-2021-41971HIGH8.8Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allow...
CVE-2021-42098HIGH8.8An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to byp...
CVE-2021-41991HIGH7.5The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests wi...
CVE-2021-41990HIGH7.5The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS sig...
CVE-2021-24754HIGH7.2The MainWP Child Reports WordPress plugin before 2.0.8 does not validate or sanitise the order parameter before using it...
CVE-2021-24684HIGH8.8The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary...
CVE-2021-38442HIGH7.8FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project...
CVE-2021-38438HIGH7.8A use after free vulnerability in FATEK Automation WinProladder versions 3.30 and prior may be exploited when a valid us...
CVE-2021-38436HIGH7.8FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project...
CVE-2021-38434HIGH7.8FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project...
CVE-2021-38430HIGH7.8FATEK Automation WinProladder versions 3.30 and prior proper validation of user-supplied data when parsing project files...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now