2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-32807HIGH7.2The module `AccessControl` defines security policies for Python code used in restricted code within Zope applications. R...
CVE-2021-27495HIGH7.1Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All ...
CVE-2021-27491HIGH7.5Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All ...
CVE-2021-35193HIGH7.5Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across di...
CVE-2021-37601HIGH7.5muc.lib.lua in Prosody 0.11.0 through 0.11.9 allows remote attackers to obtain sensitive information (list of admins, me...
CVE-2021-36983HIGH7.8replay-sorcery-kms in Replay Sorcery 0.6.0 allows a local attacker to gain root privileges via a symlink attack on /tmp/...
CVE-2021-36766HIGH7.2Concrete5 through 8.5.5 deserializes Untrusted Data. The vulnerable code is located within the controllers/single_page/d...
CVE-2021-36754HIGH7.5PowerDNS Authoritative Server 4.5.0 before 4.5.1 allows anybody to crash the process by sending a specific query (QTYPE ...
CVE-2021-36621HIGH8.1Sourcecodester Online Covid Vaccination Scheduler System 1.0 is vulnerable to SQL Injection. The username parameter is v...
CVE-2021-36386HIGH7.5report_vbuild in report.c in Fetchmail before 6.4.20 sometimes omits initialization of the vsnprintf va_list argument, w...
CVE-2021-36004HIGH8.8Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability in the CoolType library. A...
CVE-2021-35472HIGH8.8An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache corruption can lead to authorization bypass or spo...
CVE-2021-34802HIGH8.8A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow ...
CVE-2021-32610HIGH7.1In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability ...
CVE-2021-32558HIGH7.5An issue was discovered in Sangoma Asterisk 13.x before 13.38.3, 16.x before 16.19.1, 17.x before 17.9.4, and 18.x befor...
CVE-2021-31799HIGH7In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code ...
CVE-2021-28966HIGH7.5In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter w...
CVE-2021-20783HIGH8.8Cross-site request forgery (CSRF) vulnerability in Optical BB unit E-WMTA2.3 allows a remote attacker to hijack the auth...
CVE-2021-20114HIGH7.5When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the ...
CVE-2021-29736HIGH8.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the sys...
CVE-2021-36742HIGH7.8A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free B...
CVE-2021-36741HIGH8.8An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free...
CVE-2021-23415HIGH7.5This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it...
CVE-2021-32000HIGH7.1A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up i...
CVE-2021-34432HIGH7.5In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now