2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-34631HIGH8.8The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in ...
CVE-2021-32581HIGH8.1Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent ...
CVE-2021-32580HIGH7.8Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking.
CVE-2021-32579HIGH7.8Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an...
CVE-2021-32578HIGH7.8Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handl...
CVE-2021-32577HIGH7.8Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissi...
CVE-2021-32576HIGH7.8Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handl...
CVE-2021-29977HIGH8.8Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corru...
CVE-2021-29976HIGH8.8Mozilla developers reported memory safety bugs present in code shared between Firefox and Thunderbird. Some of these bug...
CVE-2021-29973HIGH8.8Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected t...
CVE-2021-29972HIGH8.8A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library r...
CVE-2021-29970HIGH8.8A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. *This...
CVE-2021-23849HIGH8.8A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected s...
CVE-2021-21863HIGH7.8A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH COD...
CVE-2021-37625HIGH7.5Skytable is an open source NoSQL database. In versions prior to 0.6.4 an incorrect check of return value of the accept f...
CVE-2021-37605HIGH7.5In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only...
CVE-2021-37604HIGH7.5In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of...
CVE-2021-38095HIGH7.5The REST API in Planview Spigit 4.5.3 allows remote unauthenticated attackers to query sensitive user accounts data, as ...
CVE-2021-36804HIGH8.1Akaunting version 2.1.12 and earlier suffers from a password reset spoofing vulnerability, wherein an attacker can proxy...
CVE-2021-36801HIGH8.1Akaunting version 2.1.12 and earlier suffers from an authentication bypass issue in the user-controllable field, compani...
CVE-2021-31869HIGH7.5Pimcore AdminBundle version 6.8.0 and earlier suffers from a SQL injection issue in the specificID variable used by the ...
CVE-2021-31867HIGH7.5Pimcore Customer Data Framework version 3.0.0 and earlier suffers from a Boolean-based blind SQL injection issue in the ...
CVE-2021-32465HIGH8.8An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 ...
CVE-2021-32464HIGH7.8An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and...
CVE-2021-22124HIGH7.5An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 throug...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now