2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40452HIGH7.8HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-40441HIGH7.8Windows Media Center Elevation of Privilege Vulnerability
CVE-2021-4116MEDIUM5.4yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-20330MEDIUM6.5An attacker with basic CRUD permissions on a replicated collection can run the applyOps command with specially malformed...
CVE-2021-4111MEDIUM4.3yetiforcecrm is vulnerable to Business Logic Errors
CVE-2021-45043HIGH7.5HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L...
CVE-2021-43326HIGH7.8Automox Agent before 32 on Windows incorrectly sets permissions on a temporary directory.
CVE-2021-43325HIGH7.8Automox Agent 33 on Windows incorrectly sets permissions on a temporary directory. NOTE: this issue exists because of a ...
CVE-2021-43113CRITICAL9.8iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mi...
CVE-2021-42945CRITICAL9.8A SQL Injection vulnerability exists in ZZCMS 2021 via the askbigclassid parameter in /admin/ask.php.
CVE-2021-42220MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation r...
CVE-2021-41560CRITICAL9.8OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUti...
CVE-2021-41557MEDIUM5.4Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cross Site Scripting (XSS). An attacker with access to a use...
CVE-2021-40827HIGH7.8Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is vulnerable to a Read Access Violation on Block ...
CVE-2021-40826HIGH7.8Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsin...
CVE-2021-40171MEDIUM5.3The absence of notifications regarding an ongoing RF jamming attack in the SecuritasHome home alarm system, version HPGW...
CVE-2021-40170MEDIUM6.8An RF replay attack vulnerability in the SecuritasHome home alarm system, version HPGW-G 0.0.2.23F BG_U-ITR-F1-BD_BL.A30...
CVE-2021-38701MEDIUM4.8Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; ...
CVE-2021-36450MEDIUM6.1Verint Workforce Optimization (WFO) 15.2.8.10048 allows XSS via the control/my_notifications NEWUINAV parameter.
CVE-2021-26787MEDIUM6.1A cross site scripting (XSS) vulnerability in Genesys Workforce Management 8.5.214.20 can occur (during record deletion)...
CVE-2021-41871MEDIUM5.4An issue was discovered in Socomec REMOTE VIEW PRO 2.0.41.4. Improper validation of input into the username field makes ...
CVE-2021-41870HIGH8.8An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can b...
CVE-2021-41844CRITICAL9.8Crocoblock JetEngine before 2.9.1 does not properly validate and sanitize form data.
CVE-2021-4110HIGH7.5mruby is vulnerable to NULL Pointer Dereference
CVE-2021-43827MEDIUM4.3discourse-footnote is a library providing footnotes for posts in Discourse. ### Impact When posting an inline footnote w...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now