2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37867MEDIUM4.3Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, w...
CVE-2021-37866HIGH7.5Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of ...
CVE-2021-37865MEDIUM5.7Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while draft...
CVE-2021-37864MEDIUM6.5Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows auth...
CVE-2021-29872MEDIUM5.4IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injec...
CVE-2021-29632HIGH7.5In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE...
CVE-2021-29215CRITICAL9.8A potential security vulnerability in HPE Ezmeral Data Fabric that may allow a remote access restriction bypass in the T...
CVE-2021-4146MEDIUM4.3Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.
CVE-2021-44217MEDIUM6.1In Ericsson CodeChecker through 6.18.0, a Stored Cross-site scripting (XSS) vulnerability in the comments component of t...
CVE-2021-41551MEDIUM4.9Leostream Connection Broker 9.0.40.17 allows administrators to conduct directory traversal attacks by uploading z ZIP fi...
CVE-2021-41550HIGH7.2Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
CVE-2021-38697CRITICAL9.8SoftVibe SARABAN for INFOMA 1.1 allows Unauthenticated unrestricted File Upload, that allows attackers to upload files w...
CVE-2021-38696HIGH7.5SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature fi...
CVE-2021-38695MEDIUM5.4SoftVibe SARABAN for INFOMA 1.1 is vulnerable to stored cross-site scripting (XSS) that allows users to store scripts in...
CVE-2021-38785HIGH7.5There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could u...
CVE-2021-38784HIGH7.5There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that coul...
CVE-2021-38694HIGH7.5SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.
CVE-2021-22566CRITICAL9.8An incorrect setting of UXN bits within mmu_flags_to_s1_pte_attr lead to privileged executable pages being mapped as exe...
CVE-2021-38783HIGH7.5There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl ...
CVE-2021-33965HIGH8.8China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by ...
CVE-2021-45394HIGH8.8An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the ...
CVE-2021-33964HIGH8.8China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives ...
CVE-2021-44757CRITICAL9.1Zoho ManageEngine Desktop Central before 10.1.2137.9 and Desktop Central MSP before 10.1.2137.9 allow attackers to bypas...
CVE-2021-42357MEDIUM6.1When using Apache Knox SSO prior to 1.6.1, a request could be crafted to redirect a user to a malicious page due to impr...
CVE-2021-38965HIGH8.8IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary com...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now