2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-36426HIGH8.8File Upload vulnerability in phpwcms 1.9.25 allows remote attackers to run arbitrary code via crafted file upload to inc...
CVE-2021-3809HIGH7.8Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi...
CVE-2021-3808HIGH7.8Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which mi...
CVE-2021-3439HIGH7.8HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being re...
CVE-2021-22786HIGH7.5A CWE-200: Information Exposure vulnerability exists that could cause the exposure of sensitive information stored on th...
CVE-2021-4315HIGH8.8A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unkn...
CVE-2021-41231HIGH7.2OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to ...
CVE-2021-41144HIGH8.8OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the blo...
CVE-2021-41143HIGH7.2OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the cu...
CVE-2021-39217HIGH7.2OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to exec...
CVE-2021-41989HIGH7.8Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2021-41988HIGH7.8Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
CVE-2021-28510HIGH7.5For certain systems running EOS, a Precision Time Protocol (PTP) packet of a management/signaling message with an invali...
CVE-2021-43449HIGH8.1ONLYOFFICE all versions as of 2021-11-08 is vulnerable to Server-Side Request Forgery (SSRF). The document editor servic...
CVE-2021-43447HIGH7.5ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An authentication bypass in the docume...
CVE-2021-43444HIGH7.5ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be f...
CVE-2021-24881HIGH7.5The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed...
CVE-2021-33641HIGH7.8When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses...
CVE-2021-29368HIGH8.8Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 all...
CVE-2021-37500HIGH8.1Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics funct...
CVE-2021-27782HIGH7.5HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked ou...
CVE-2021-37774HIGH8An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code...
CVE-2021-33959HIGH7.5Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
CVE-2021-36630HIGH7.5DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote at...
CVE-2021-32837HIGH7.5mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerab...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now