2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37262HIGH7.5JFinal_cms 5.1.0 is vulnerable to regex injection that may lead to Denial of Service.
CVE-2021-41962MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fu...
CVE-2021-41260HIGH8.8Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions...
CVE-2021-42912HIGH8.8FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows th...
CVE-2021-3960HIGH7.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the UpdateServer compone...
CVE-2021-3959HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security To...
CVE-2021-4124MEDIUM6.1janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-40835MEDIUM4.3An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafte...
CVE-2021-4123MEDIUM6.5livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4121MEDIUM6.1yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-45102HIGH8.8An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon...
CVE-2021-45101HIGH8.1An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2. Using standard command-li...
CVE-2021-45100HIGH7.5The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even tho...
CVE-2021-45099HIGH8.8The addon.stdin service in addon-ssh (aka Home Assistant Community Add-on: SSH & Web Terminal) before 10.0.0 has an atta...
CVE-2021-45098HIGH7.5An issue was discovered in Suricata before 6.0.4. It is possible to bypass/evade any HTTP-based signature by faking an R...
CVE-2021-45097MEDIUM5.5KNIME Server before 4.12.6 and 4.13.x before 4.13.4 (when installed in unattended mode) keeps the administrator's passwo...
CVE-2021-45096MEDIUM4.3KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a crafted workflow file (...
CVE-2021-45095MEDIUM5.5pep_sock_accept in net/phonet/pep.c in the Linux kernel through 5.15.8 has a refcount leak.
CVE-2021-45092CRITICAL9.8Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi...
CVE-2021-45088MEDIUM6.1XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an error page.
CVE-2021-45087MEDIUM6.1XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 when View Source mode or Reader mode is used,...
CVE-2021-45086MEDIUM6.1XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 because a server's suggested_filename is used...
CVE-2021-45085MEDIUM6.1XSS can occur in GNOME Web (aka Epiphany) before 40.4 and 41.x before 41.1 via an about: page, as demonstrated by ephy-a...
CVE-2021-44023HIGH7.1A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products c...
CVE-2021-43834CRITICAL9.8eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now