2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-32816HIGH7.5ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Clien...
CVE-2021-20393HIGH7.5IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information whe...
CVE-2021-24280HIGH8.8In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could...
CVE-2021-24278HIGH7.5In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, unauthenticated users can use the wpcf7r_get_nonce ...
CVE-2021-24195HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login as User or Customer ...
CVE-2021-24194HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Login Protection - Limit F...
CVE-2021-24193HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Visitor Traffic Real Time ...
CVE-2021-24192HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Tree Sitemap WordPress plu...
CVE-2021-24191HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Maintenance Mode & Site...
CVE-2021-24190HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WooCommerce Conditional Ma...
CVE-2021-24189HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the Captchinoo, Google recaptc...
CVE-2021-24188HIGH8.8Low privileged users can use the AJAX action 'cp_plugins_do_button_job_later_callback' in the WP Content Copy Protection...
CVE-2021-30183HIGH7.5Cleartext storage of sensitive information in multiple versions of Octopus Server where in certain situations when runni...
CVE-2021-32051HIGH7.5Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id par...
CVE-2021-31922HIGH7.5An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to s...
CVE-2021-29510HIGH7.5Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'i...
CVE-2021-27413HIGH7.8Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based b...
CVE-2021-22140HIGH7.5Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the A...
CVE-2021-32920HIGH7.5Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
CVE-2021-32919HIGH7.5An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enab...
CVE-2021-32918HIGH7.5An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-s...
CVE-2021-20181HIGH7.5A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a ...
CVE-2021-3528HIGH8.8A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator ...
CVE-2021-20025HIGH7.8SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password...
CVE-2021-25693HIGH7.5An attacker may cause a Denial of Service (DoS) in multiple versions of Teradici PCoIP Agent via a null pointer derefere...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now