2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-37543HIGH8.8In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.
CVE-2021-36708HIGH7.5In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the...
CVE-2021-37381HIGH8.8Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos t...
CVE-2021-3580HIGH7.5A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could us...
CVE-2021-37632HIGH8.1SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn6...
CVE-2021-37156HIGH7.5Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's ...
CVE-2021-35326HIGH7.5A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configura...
CVE-2021-35325HIGH7.5A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers...
CVE-2021-34639HIGH8.8Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files w...
CVE-2021-34634HIGH8.8The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function foun...
CVE-2021-34633HIGH8.8The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in...
CVE-2021-28216HIGH7.8BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3S...
CVE-2021-26586HIGH7.5A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edg...
CVE-2021-22928HIGH7.8A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Wind...
CVE-2021-22927HIGH8.1A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provide...
CVE-2021-22926HIGH7.5libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CU...
CVE-2021-22919HIGH7.5A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known a...
CVE-2021-22517HIGH8.8A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector. The vulne...
CVE-2021-21893HIGH8.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.0.0.49893. A s...
CVE-2021-21870HIGH8.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.4.37651. A s...
CVE-2021-21831HIGH8.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A s...
CVE-2021-20592HIGH7.5Missing synchronization vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.39...
CVE-2021-1630HIGH7.5XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub,...
CVE-2021-3682HIGH8.5A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping ...
CVE-2021-37614HIGH8.8In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web appl...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now