2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43960MEDIUM4.8Lorensbergs Connect2 3.13.7647.20190 is affected by an XSS vulnerability. Exploitation requires administrator privileges...
CVE-2021-42562HIGH8.1An issue was discovered in CALDERA 2.8.1. It does not properly segregate user privileges, resulting in non-admin users h...
CVE-2021-42561HIGH8.8An issue was discovered in CALDERA 2.8.1. When activated, the Human plugin passes the unsanitized name parameter to a py...
CVE-2021-42560HIGH8.8An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a ...
CVE-2021-36417HIGH7.8A heap-based buffer overflow vulnerability exists in GPAC v1.0.1 in the gf_isom_dovi_config_get function in MP4Box, whic...
CVE-2021-35500MEDIUM5.5The Data Virtualization Server component of TIBCO Software Inc.'s TIBCO Data Virtualization, TIBCO Data Virtualization, ...
CVE-2021-45445HIGH7.5Unisys ClearPath MCP TCP/IP Networking Services 59.1, 60.0, and 62.0 has an Infinite Loop.
CVE-2021-28377MEDIUM5.3ChronoForums 2.0.11 allows av Directory Traversal to read arbitrary files.
CVE-2021-28376LOW2.7ChronoForms 7.0.7 allows fname Directory Traversal to read arbitrary files.
CVE-2021-45411CRITICAL9.8In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database via SQLi, an attacker can...
CVE-2021-45388Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-45608. Reason: This candidate is a reservation d...
CVE-2021-43436MEDIUM5.4MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. ...
CVE-2021-38892Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-44652HIGH7.8Zoho ManageEngine O365 Manager Plus before Build 4416 allows remote code execution via BCP file overwrite through the Ch...
CVE-2021-44651HIGH8.8Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the updatePersonalizeSettings...
CVE-2021-4080HIGH8.8crater is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2021-44650HIGH7.2Zoho ManageEngine M365 Manager Plus before Build 4419 allows remote command execution when updating proxy settings throu...
CVE-2021-44649MEDIUM5.4Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type,...
CVE-2021-44648HIGH8.8GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of...
CVE-2021-3852HIGH7.5growi is vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2021-46283MEDIUM5.5nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denia...
CVE-2021-43999HIGH8.8Apache Guacamole 1.2.0 and 1.3.0 do not properly validate responses received from a SAML identity provider. If SAML supp...
CVE-2021-41767MEDIUM6.5Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some ...
CVE-2021-43974MEDIUM5.3An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, ...
CVE-2021-43973HIGH8.8An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now