2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43764MEDIUM5.4AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a stored Cross-Site Scripting (XSS...
CVE-2021-43762MEDIUM6.5AEM's Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by a dispatcher bypass vulnerability ...
CVE-2021-43761MEDIUM5.4AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are a...
CVE-2021-40722CRITICAL9.8AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) i...
CVE-2021-33046CRITICAL9.8Some Dahua products have access control vulnerability in the password reset process. Attackers can exploit this vulnerab...
CVE-2021-23227HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions.
CVE-2021-45807CRITICAL9.8jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
CVE-2021-45422MEDIUM6.1Reprise License Manager 14.2 is affected by a reflected cross-site scripting vulnerability in the /goform/activate_proce...
CVE-2021-40576MEDIUM5.5The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the gf_isom_get_payt_count function in h...
CVE-2021-40575MEDIUM5.5The binary MP4Box in Gpac 1.0.1 has a null pointer dereference vulnerability in the mpgviddmx_process function in refram...
CVE-2021-40574HIGH7.8The binary MP4Box in Gpac from 0.9.0-preview to 1.0.1 has a double-free vulnerability in the gf_text_get_utf8_line funct...
CVE-2021-40573MEDIUM5.5The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the gf_list_del function in list.c, which allows atta...
CVE-2021-40572MEDIUM5.5The binary MP4Box in Gpac 1.0.1 has a double-free bug in the av1dmx_finalize function in reframe_av1.c, which allows att...
CVE-2021-40813MEDIUM5.4A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote...
CVE-2021-40571HIGH7.8The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the ilst_box_read function in box_code_apple.c, which...
CVE-2021-40570HIGH7.8The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avc_compute_poc function in av_parsers.c, which a...
CVE-2021-40569MEDIUM5.5The binary MP4Box in Gpac through 1.0.1 has a double-free vulnerability in the iloc_entry_del funciton in box_code_meta....
CVE-2021-40568HIGH7.8A buffer overflow vulnerability exists in Gpac through 1.0.1 via a malformed MP4 file in the svc_parse_slice function in...
CVE-2021-40567MEDIUM5.5Segmentation fault vulnerability exists in Gpac through 1.0.1 via the gf_odf_size_descriptor function in desc_private.c ...
CVE-2021-39056MEDIUM6.5The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to ...
CVE-2021-40327MEDIUM5.9Trusted Firmware-M (TF-M) 1.4.0, when Profile Small is used, has incorrect access control. NSPE can access a secure key ...
CVE-2021-23824MEDIUM6.1This affects the package Crow before 0.3+4. When using attributes without quotes in the template, an attacker can manipu...
CVE-2021-45806HIGH8.8jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious ...
CVE-2021-23514HIGH7.5This affects the package Crow before 0.3+4. It is possible to traverse directories to fetch arbitrary files from the ser...
CVE-2021-30353HIGH7.5Improper validation of function pointer type with actual function signature can lead to assertion in Snapdragon Auto, Sn...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now