2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36347HIGH7.2iDRAC9 versions prior to 5.00.20.00 and iDRAC8 versions prior to 2.82.82.82 contain a stack-based buffer overflow vulner...
CVE-2021-36346MEDIUM5.3Dell iDRAC 8 prior to version 2.82.82.82 contain a denial of service vulnerability. An unauthenticated remote attacker c...
CVE-2021-36296HIGH7.2Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A r...
CVE-2021-36295HIGH7.2Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A r...
CVE-2021-36294CRITICAL9.8Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authentication bypass vulnerability. A remote unauthen...
CVE-2021-36289HIGH7.8Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain a sensitive information disclosure vulnerability. A local...
CVE-2021-43799CRITICAL9.8Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In version...
CVE-2021-4145MEDIUM6.5A NULL pointer dereference issue was found in the block mirror layer of QEMU in versions prior to 6.2.0. The `self` poin...
CVE-2021-4133HIGH8.8A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user a...
CVE-2021-45729MEDIUM5.4The Privilege Escalation vulnerability discovered in the WP Google Map WordPress plugin (versions <= 1.8.0) allows authe...
CVE-2021-43298CRITICAL9.8The code that performs password matching when using 'Basic' HTTP authentication does not use a constant-time memcmp and ...
CVE-2021-41598HIGH8.8A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be gran...
CVE-2021-40337MEDIUM5.4Cross-site Scripting (XSS) vulnerability in Hitachi Energy LinkOne allows an attacker that manages to exploit the vulner...
CVE-2021-40167HIGH7.8A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption ...
CVE-2021-40159HIGH7.8An Information Disclosure vulnerability for JT files in Autodesk Inventor 2022, 2021, 2020, 2019 in conjunction with oth...
CVE-2021-40158HIGH7.8A maliciously crafted JT file in Autodesk Inventor 2022, 2021, 2020, 2019 and AutoCAD 2022 may be forced to read beyond ...
CVE-2021-38129LOW3.3Escalation of privileges vulnerability in Micro Focus in Micro Focus Operations Agent, affecting versions 12.x up to and...
CVE-2021-39031HIGH8.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 22.0.0.1 could allow a remote authenticated attacker to cond...
CVE-2021-46087MEDIUM5.4In jfinal_cms >= 5.1 0, there is a storage XSS vulnerability in the background system of CMS. Because developers do not ...
CVE-2021-46086HIGH7.5xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examina...
CVE-2021-46085MEDIUM6.5OneBlog <= 2.2.8 is vulnerable to Insecure Permissions. Low level administrators can delete high-level administrators be...
CVE-2021-46084MEDIUM5.4uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via "close registration information" input box.
CVE-2021-46083MEDIUM5.4uscat, as of 2021-12-28, is vulnerable to Cross Site Scripting (XSS) via the input box of the statistical code.
CVE-2021-46034MEDIUM6.1A problem was found in ForestBlog, as of 2021-12-29, there is a XSS vulnerability that can be injected through the nickn...
CVE-2021-43863HIGH7.5The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. The Nextcloud Androi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now