2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44942MEDIUM4.3glFusion CMS 1.7.9 is affected by a Cross Site Request Forgery (CSRF) vulnerability in /public_html/admin/plugins/bad_be...
CVE-2021-4108MEDIUM6.1snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-44948Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-44942. Reason: This candidate is a duplicate of ...
CVE-2021-43830HIGH8.8OpenProject is a web-based project management software. OpenProject versions >= 12.0.0 are vulnerable to a SQL injection...
CVE-2021-43829HIGH8.8PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.7.7 PatrowlMana...
CVE-2021-43828HIGH7.5PatrOwl is a free and open-source solution for orchestrating Security Operations. In versions prior to 1.77 an improper ...
CVE-2021-43821HIGH7.7Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast before version 9.10 or 10.6 allows...
CVE-2021-43051MEDIUM6.8The Spotfire Server component of TIBCO Software Inc.'s TIBCO Spotfire Server, TIBCO Spotfire Server, and TIBCO Spotfire ...
CVE-2021-39183MEDIUM6.1Owncast is an open source, self-hosted live video streaming and chat server. In affected versions inline scripts are exe...
CVE-2021-34426HIGH7.8A vulnerability was discovered in the Keybase Client for Windows before version 5.6.0 when a user executed the "keybase ...
CVE-2021-34425MEDIUM6.1The Zoom Client for Meetings before version 5.7.3 (for Android, iOS, Linux, macOS, and Windows) contain a server side re...
CVE-2021-4044HIGH7.5Internally libssl in OpenSSL calls X509_verify_cert() on the client side to verify a certificate supplied by a server. T...
CVE-2021-45046CRITICAL9It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configu...
CVE-2021-43820MEDIUM5.9Seafile is an open source cloud storage system. A sync token is used in Seafile file syncing protocol to authorize acces...
CVE-2021-40883CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
CVE-2021-44043MEDIUM5.4An issue was discovered in UiPath App Studio 21.4.4. There is a persistent XSS vulnerability in the file-upload function...
CVE-2021-44042CRITICAL9.8An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the...
CVE-2021-44041CRITICAL9.8UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget a...
CVE-2021-43807MEDIUM6.5Opencast is an Open Source Lecture Capture & Video Management for Education. Opencast versions prior to 9.10 allow HTTP ...
CVE-2021-43388HIGH7.5Unisys Cargo Mobile Application before 1.2.29 uses cleartext to store sensitive information, which might be revealed in ...
CVE-2021-40882MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the loca...
CVE-2021-38950HIGH7.8IBM MQ on HPE NonStop 8.0.4 and 8.1.0 is vulnerable to a privilege escalation attack when SharedBindingsUserId is set to...
CVE-2021-4073HIGH8.1The RegistrationMagic WordPress plugin made it possible for unauthenticated users to log in as any site user, including ...
CVE-2021-44549HIGH7.4Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via S...
CVE-2021-44235MEDIUM6.7Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now