2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44777MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email ...
CVE-2021-3816MEDIUM5.4Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix fi...
CVE-2021-26247MEDIUM6.1As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" t...
CVE-2021-23843HIGH7.8The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices....
CVE-2021-23842HIGH7.1Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An a...
CVE-2021-23225MEDIUM5.4Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "...
CVE-2021-38789HIGH7.5Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the c...
CVE-2021-46204CRITICAL9.8Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter. SQL injection vulne...
CVE-2021-46203MEDIUM6.5Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter.
CVE-2021-44299MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows au...
CVE-2021-42810HIGH7.8A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a priv...
CVE-2021-33913CRITICAL9.8libspf2 before 1.2.11 has a heap-based buffer overflow that might allow remote attackers to execute arbitrary code (via ...
CVE-2021-33912CRITICAL9.8libspf2 before 1.2.11 has a four-byte heap-based buffer overflow that might allow remote attackers to execute arbitrary ...
CVE-2021-38788HIGH7.5The Background service in Allwinner R818 SoC Android Q SDK V1.0 is used to manage background applications. Malicious app...
CVE-2021-46030MEDIUM5.4There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into t...
CVE-2021-44837MEDIUM4.3An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an ad...
CVE-2021-46104HIGH7.5An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi...
CVE-2021-45808HIGH8.8jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the s...
CVE-2021-38787HIGH7.5There is an integer overflow in the ION driver "/dev/ion" of Allwinner R818 SoC Android Q SDK V1.0 that could use the io...
CVE-2021-38786HIGH7.5There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could ca...
CVE-2021-35687MEDIUM5.3Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2021-35686MEDIUM4.3Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2021-35683CRITICAL9.9Vulnerability in the Oracle Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supp...
CVE-2021-35587CRITICAL9.8Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: OpenSSO Agent). Supported ver...
CVE-2021-31854HIGH7.8A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now