2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-35254HIGH8.8SolarWinds received a report of a vulnerability related to an input that was not sanitized in WebHelpDesk. SolarWinds ha...
CVE-2021-26622CRITICAL10An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was dis...
CVE-2021-26621CRITICAL9.8An Buffer Overflow vulnerability leading to remote code execution was discovered in MEX01. Remote attackers can use this...
CVE-2021-26620HIGH7.5An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attack...
CVE-2021-22100MEDIUM5.3In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker...
CVE-2021-20323MEDIUM6.1A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
CVE-2021-20290MEDIUM6.1An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman cli...
CVE-2021-43636CRITICAL9.8Two Buffer Overflow vulnerabilities exists in T10 V2_Firmware V4.1.8cu.5207_B20210320 in the http_request_parse function...
CVE-2021-43091HIGH7.5An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form.
CVE-2021-46426MEDIUM6.1phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functiona...
CVE-2021-43090CRITICAL9.8An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function.
CVE-2021-44751MEDIUM5.3A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in...
CVE-2021-43666HIGH7.5A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an...
CVE-2021-43085Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-43084CRITICAL9.8An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.
CVE-2021-39491MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan ...
CVE-2021-43659MEDIUM5.4In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, wh...
CVE-2021-43700CRITICAL9.8An issue was discovered in ApiManager 1.1. there is sql injection vulnerability that can use in /index.php?act=api&tag=8...
CVE-2021-31326CRITICAL9.8D-Link DIR-816 A2 1.10 B05 allows unauthenticated attackers to arbitrarily reset the device via a crafted tokenid parame...
CVE-2021-44226HIGH7.3Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Servi...
CVE-2021-28278HIGH7.8A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c...
CVE-2021-28277HIGH7.8A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUn...
CVE-2021-28276HIGH7.5A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir ...
CVE-2021-28275MEDIUM5.5A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exi...
CVE-2021-4219MEDIUM5.5A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now