2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45452MEDIUM5.3Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted ...
CVE-2021-45116HIGH7.5An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Djan...
CVE-2021-45115HIGH7.5An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityVal...
CVE-2021-41388HIGH7.8Netskope client prior to 89.x on macOS is impacted by a local privilege escalation vulnerability. The XPC implementation...
CVE-2021-22045HIGH7.8VMware ESXi (7.0, 6.7 before ESXi670-202111101-SG and 6.5 before ESXi650-202110101-SG), VMware Workstation (16.2.0) and ...
CVE-2021-43852HIGH8.8OroPlatform is a PHP Business Application Platform. In affected versions by sending a specially crafted request, an atta...
CVE-2021-43850MEDIUM6.8Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of...
CVE-2021-43832CRITICAL9.8Spinnaker is an open source, multi-cloud continuous delivery platform. Spinnaker has improper permissions allowing pipel...
CVE-2021-43677MEDIUM6.1Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability.
CVE-2021-41610Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-27339. Reason: This candidate is a reservation d...
CVE-2021-41236MEDIUM4.8OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS...
CVE-2021-41141HIGH7.5PJSIP is a free and open source multimedia communication library written in the C language implementing standard based p...
CVE-2021-24042CRITICAL9.8The calling logic for WhatsApp for Android prior to v2.21.23, WhatsApp Business for Android prior to v2.21.23, WhatsApp ...
CVE-2021-39143HIGH7.1Spinnaker is an open source, multi-cloud continuous delivery platform. A path traversal vulnerability was discovered in ...
CVE-2021-3845HIGH7.5ws-scrcpy is vulnerable to External Control of File Name or Path
CVE-2021-45912HIGH7.8An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attack...
CVE-2021-45389CRITICAL9.8A flaw was found with the JWT token. A self-signed JWT token could be injected into the update manager and bypass the au...
CVE-2021-41789MEDIUM6.5In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of ...
CVE-2021-40148HIGH7.5In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote inf...
CVE-2021-45980HIGH7.8Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via getURL in the ...
CVE-2021-45979HIGH7.8Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL ...
CVE-2021-45978HIGH7.8Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoU...
CVE-2021-45913HIGH7.2A hardcoded key in ControlUp Real-Time Agent (cuAgent.exe) before 8.2.5 may allow a potential attacker to run OS command...
CVE-2021-3842HIGH7.5nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-43711CRITICAL9.8The downloadFlile.cgi binary file in TOTOLINK EX200 V4.0.3c.7646_B20201211 has a command injection vulnerability when re...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now