2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-33007HIGH7.8A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a speciall...
CVE-2021-29631HIGH7.8In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE...
CVE-2021-27020HIGH8.8Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
CVE-2021-27018HIGH7.5The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed b...
CVE-2021-22027HIGH7.5The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauth...
CVE-2021-22026HIGH7.5The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauth...
CVE-2021-22025HIGH7.5The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthe...
CVE-2021-22024HIGH7.5The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthentic...
CVE-2021-22023HIGH7.2The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor wi...
CVE-2021-29723HIGH7.5IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou...
CVE-2021-29722HIGH7.5IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 uses weaker than expected cryptographic algorithms that cou...
CVE-2021-37911HIGH8.8The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attacke...
CVE-2021-24581HIGH8.8The Blue Admin WordPress plugin through 21.06.01 does not sanitise or escape its "Logo Title" setting before outputting ...
CVE-2021-24580HIGH8.8The Side Menu Lite WordPress plugin before 2.2.6 does not sanitise user input from the List page in the admin dashboard ...
CVE-2021-24579HIGH8.8The bt_bb_get_grid AJAX action of the Bold Page Builder WordPress plugin before 3.1.6 passes user input into the unseria...
CVE-2021-25958HIGH7.5In Apache Ofbiz, versions v17.12.01 to v17.12.07 implement a try catch exception to handle errors at multiple locations ...
CVE-2021-39113HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached c...
CVE-2021-39271HIGH8.8OrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attack...
CVE-2021-38385HIGH7.5Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-s...
CVE-2021-36359HIGH8.8OrbiTeam BSCW Classic before 7.4.3 allows exportpdf authenticated remote code execution (RCE) via XML tag injection beca...
CVE-2021-40174HIGH8.8Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
CVE-2021-40173HIGH8.8Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.
CVE-2021-40172HIGH8.8Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.
CVE-2021-38154HIGH7.5Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server ...
CVE-2021-39174HIGH8.8Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now