2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-41947HIGH7.2A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
CVE-2021-42095HIGH7.5Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.
CVE-2021-42089HIGH7.5An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.
CVE-2021-42086HIGH8.8An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a c...
CVE-2021-42093HIGH7.2An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manip...
CVE-2021-20584HIGH7.5IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by imp...
CVE-2021-20489HIGH8.8IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attac...
CVE-2021-40726HIGH7.8Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a...
CVE-2021-40725HIGH7.8Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a...
CVE-2021-28129HIGH7.8While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but ins...
CVE-2021-41794HIGH7.5ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer...
CVE-2021-35067HIGH8.1Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who snif...
CVE-2021-33903HIGH8.8In LCOS 10.40 to 10.42.0473-RU3 with SNMPv3 enabled on LANCOM devices, changing the password of the root user via the CL...
CVE-2021-40978HIGH7.5The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obt...
CVE-2021-41770HIGH7.5Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XM...
CVE-2021-42054HIGH7.5ACCEL-PPP 1.12.0 has an out-of-bounds read in triton_context_schedule if the client exits after authentication.
CVE-2021-26557HIGH7.8When Octopus Tentacle is installed using a custom folder location, folder ACLs are not set correctly and could lead to a...
CVE-2021-26556HIGH7.8When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an ...
CVE-2021-42040HIGH7.5An issue was discovered in MediaWiki through 1.36.2. A parser function related to loop control allowed for an infinite l...
CVE-2021-41129HIGH8.1Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify ...
CVE-2021-34788HIGH7A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS ...
CVE-2021-34780HIGH8.8Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S...
CVE-2021-34779HIGH8.8Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business 220 S...
CVE-2021-34766HIGH8.8A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote...
CVE-2021-34748HIGH8.8A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now