2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-32773HIGH7.5Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior t...
CVE-2021-31590HIGH8.8PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect access control. ...
CVE-2021-34820HIGH7.5Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for ...
CVE-2021-36799HIGH8.8KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local use...
CVE-2021-34676HIGH7.5Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.
CVE-2021-34675HIGH7.5Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.
CVE-2021-29707HIGH7.8IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to...
CVE-2021-35449HIGH7.8The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below,...
CVE-2021-20109HIGH7.5Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure t...
CVE-2021-20108HIGH7.5Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Serve...
CVE-2021-31216HIGH8.1Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (...
CVE-2021-24453HIGH8.8The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to ...
CVE-2021-36773HIGH7.5uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking...
CVE-2021-36213HIGH7.5HashiCorp Consul and Consul Enterprise 1.9.0 through 1.10.0 default deny policy with a single L7 application-aware inten...
CVE-2021-32574HIGH7.5HashiCorp Consul and Consul Enterprise 1.3.0 through 1.10.0 Envoy proxy TLS configuration does not validate destination ...
CVE-2021-3550HIGH7.8A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privil...
CVE-2021-34481HIGH8.8A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file ...
CVE-2021-34467HIGH7.1Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2021-34464HIGH7.8Microsoft Defender Remote Code Execution Vulnerability
CVE-2021-34462HIGH7Windows AppX Deployment Extensions Elevation of Privilege Vulnerability
CVE-2021-34461HIGH7.8Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability
CVE-2021-34460HIGH7.8Windows Storage Spaces Controller Elevation of Privilege Vulnerability
CVE-2021-34459HIGH7.8Windows AppContainer Elevation Of Privilege Vulnerability
CVE-2021-34456HIGH7.8Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2021-34455HIGH7.8Windows File History Service Elevation of Privilege Vulnerability

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now