2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43833HIGH8.8eLabFTW is an electronic lab notebook manager for research teams. In versions prior to 4.2.0 there is a vulnerability wh...
CVE-2021-45018MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Catfish <=6.3.0 via a Google search in url:/catfishcms/index.php/admi...
CVE-2021-45017HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exits in Catfish <=6.1.* when you upload an html file containing CSRF on...
CVE-2021-44350CRITICAL9.8SQL Injection vulnerability exists in ThinkPHP5 5.0.x <=5.1.22 via the parseOrder function in Builder.php.
CVE-2021-44116MEDIUM6.1Cross Site Scripting (XSS) vulnerability exits in Anchor CMS <=0.12.7 in posts.php. Attackers can use the posts column t...
CVE-2021-4119CRITICAL9.8bookstack is vulnerable to Improper Access Control
CVE-2021-45078HIGH7.8stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-base...
CVE-2021-43836HIGH8.8Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker ca...
CVE-2021-43835HIGH7.2Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who...
CVE-2021-43831HIGH7.7Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5....
CVE-2021-43806HIGH8.8Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected v...
CVE-2021-43782HIGH7.2Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. This is a fol...
CVE-2021-41276HIGH7.2Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In affected v...
CVE-2021-35490MEDIUM5.4Thruk before 2.44 allows XSS for a quick command.
CVE-2021-29847MEDIUM5.9BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user t...
CVE-2021-27859HIGH8.8A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior t...
CVE-2021-27858MEDIUM5.3A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior t...
CVE-2021-27857HIGH7.5A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior t...
CVE-2021-27856CRITICAL9.8FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" ...
CVE-2021-27855HIGH8.8FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated atta...
CVE-2021-43935CRITICAL9.8The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulner...
CVE-2021-39657MEDIUM4.4In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. Thi...
CVE-2021-39656MEDIUM6.7In __configfs_open_file of file.c, there is a possible use-after-free due to improper locking. This could lead to local ...
CVE-2021-39655CRITICAL9.8Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A
CVE-2021-39653HIGH7.8In (TBD) of (TBD), there is a possible way to boot with a hidden debug policy due to a missing warning to the user. This...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now