2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-42333HIGH8.8The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL c...
CVE-2021-42330HIGH8.8The “Teacher Edit” function of ShinHer StudyOnline System does not perform authority control. After logging in with user...
CVE-2021-40999HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas...
CVE-2021-42340HIGH7.5The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60...
CVE-2021-38295HIGH7.3In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachmen...
CVE-2021-36389HIGH7.5In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Ref...
CVE-2021-36388HIGH7.5In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Obj...
CVE-2021-42369HIGH8.8Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject ...
CVE-2021-42228HIGH8.8A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.h...
CVE-2021-38346HIGH8.8The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a locati...
CVE-2021-37933HIGH7.5An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, r...
CVE-2021-33177HIGH8.8The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation r...
CVE-2021-22964HIGH8.8A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect...
CVE-2021-20599HIGH7.5Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC i...
CVE-2021-42341HIGH7.5checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for the...
CVE-2021-40854HIGH7.8AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Cha...
CVE-2021-40843HIGH7.3Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An atta...
CVE-2021-20131HIGH8.8ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope...
CVE-2021-20130HIGH8.8ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope...
CVE-2021-3057HIGH8.1A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the...
CVE-2021-20129HIGH7.5An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to...
CVE-2021-20127HIGH8.1An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek...
CVE-2021-20126HIGH8.8Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a we...
CVE-2021-20124HIGH7.5A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the W...
CVE-2021-20123HIGH7.5A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the D...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now