2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-23893HIGH7.8Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow...
CVE-2021-3747HIGH7.8The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with inc...
CVE-2021-3626HIGH8.8The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket t...
CVE-2021-33626HIGH7.8A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently ...
CVE-2021-29894HIGH7.5IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorit...
CVE-2021-41109HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2021-41302HIGH7.3ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely...
CVE-2021-41298HIGH8.8ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct a...
CVE-2021-41297HIGH8.8ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate priv...
CVE-2021-41295HIGH8.8ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a for...
CVE-2021-41293HIGH7.5ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific ...
CVE-2021-41291HIGH7.5ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Mana...
CVE-2021-41829HIGH7.5Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain ...
CVE-2021-41828HIGH7.5Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
CVE-2021-41827HIGH7.5Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials ...
CVE-2021-41824HIGH8.8Craft CMS before 3.7.14 allows CSV injection.
CVE-2021-41034HIGH8.1The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoin...
CVE-2021-41764HIGH8.8A cross-site request forgery (CSRF) vulnerability exists in Streama up to and including v1.10.3. The application does no...
CVE-2021-3653HIGH8.8A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMC...
CVE-2021-39342HIGH7.5The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaint...
CVE-2021-35945HIGH7.5Couchbase Server 6.5.x, 6.6.0 through 6.6.2, and 7.0.0, has a Buffer Overflow. A specially crafted network packet sent f...
CVE-2021-35944HIGH7.5Couchbase Server 6.5.x, 6.6.x through 6.6.2, and 7.0.0 has a Buffer Overflow. A specially crafted network packet sent fr...
CVE-2021-22946HIGH7.5A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FT...
CVE-2021-41732HIGH7.5An issue was discovered in zeek version 4.1.0. There is a HTTP request splitting vulnerability that will invalidate any ...
CVE-2021-23446HIGH7.5The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now