2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42712HIGH7.8Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2021-41552HIGH8.8CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.
CVE-2021-46558MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to e...
CVE-2021-46557MEDIUM5.4Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs.
CVE-2021-43948MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi...
CVE-2021-43941MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including...
CVE-2021-43940HIGH7.8Affected versions of Atlassian Confluence Server and Data Center allow authenticated local attackers to achieve elevated...
CVE-2021-43953MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread C...
CVE-2021-43950MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi...
CVE-2021-43952MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to restore the default...
CVE-2021-4201CRITICAL9.8Missing access control in ForgeRock Access Management 7.1.0 and earlier versions on all platforms allows remote unauthen...
CVE-2021-46463CRITICAL9.8njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerabili...
CVE-2021-46462HIGH7.5njs through 0.7.1, used in NGINX, was discovered to contain a segmentation violation via njs_object_set_prototype in /sr...
CVE-2021-46461CRITICAL9.8njs through 0.7.0, used in NGINX, was discovered to contain an out-of-bounds array access via njs_vmcode_typeof in /src/...
CVE-2021-45005CRITICAL9.8Artifex MuJS v1.1.3 was discovered to contain a heap buffer overflow which is caused by conflicting JumpList of nested t...
CVE-2021-45310MEDIUM5.3Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to ...
CVE-2021-45348HIGH7.5An Arbitrary File Deletion vulnerability exists in SourceCodester Attendance Management System v1.0 via the csv paramete...
CVE-2021-43106MEDIUM6.1A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface Tranzware Online (TWO) 5.3.3...
CVE-2021-45347HIGH7.5An Incorrect Access Control vulnerability exists in zzcms 8.2, which lets a malicious user bypass authentication by chan...
CVE-2021-45346MEDIUM4.3A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made...
CVE-2021-39080MEDIUM6.5Due to weak obfuscation, IBM Cognos Analytics Mobile for Android application prior to version 1.1.14 , an attacker could...
CVE-2021-39079MEDIUM5.4IBM Cognos Analytics Mobile for Android applications prior to version 1.1.14 is vulnerable to cross-site scripting. This...
CVE-2021-45392HIGH7.5A Buffer Overflow vulnerability exists in Tenda Router AX12 V22.03.01.21_CN in the sub_422CE4 function in page /goform/s...
CVE-2021-46371HIGH7.5antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the...
CVE-2021-45421HIGH7.5Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now