2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24705MEDIUM4.8The NEX-Forms WordPress plugin before 8.4.3 does not have CSRF checks in place when editing a form, and does not escape ...
CVE-2021-20867MEDIUM6.5Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au...
CVE-2021-20866MEDIUM6.5Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au...
CVE-2021-20865HIGH7.5Advanced Custom Fields versions prior to 5.11 and Advanced Custom Fields Pro versions prior to 5.11 contain a missing au...
CVE-2021-44155MEDIUM5.3An issue was discovered in /goform/login_process in Reprise RLM 14.2. When an attacker attempts to login, the response i...
CVE-2021-44154HIGH7.2An issue was discovered in Reprise RLM 14.2. By using an admin account, an attacker can write a payload to /goform/edit_...
CVE-2021-44153HIGH7.2An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable a...
CVE-2021-44152CRITICAL9.8An issue was discovered in Reprise RLM 14.2. Because /goform/change_password_process does not verify authentication or a...
CVE-2021-44151HIGH7.5An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can hijack any existing sessi...
CVE-2021-40858MEDIUM4.9Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin pa...
CVE-2021-40857HIGH8.8Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.
CVE-2021-40856HIGH7.5Auerswald COMfortel 1400 IP and 2600 IP before 2.8G devices allow Authentication Bypass via the /about/../ substring.
CVE-2021-44848MEDIUM5.3In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques...
CVE-2021-44847CRITICAL9.8A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2....
CVE-2021-44833CRITICAL9.8The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
CVE-2021-44515CRITICAL9.8Zoho ManageEngine Desktop Central is vulnerable to authentication bypass, leading to remote code execution on the server...
CVE-2021-41805HIGH8.8HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. A...
CVE-2021-4097MEDIUM5.4phpservermon is vulnerable to Improper Neutralization of CRLF Sequences
CVE-2021-4092MEDIUM4.3yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-41242HIGH8.1OpenOlat is a web-basedlearning management system. A path traversal vulnerability exists in OpenOlat prior to versions 1...
CVE-2021-26340HIGH8.4A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to fl...
CVE-2021-43815MEDIUM4.3Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a di...
CVE-2021-4089MEDIUM4.3snipe-it is vulnerable to Improper Access Control
CVE-2021-23700CRITICAL9.8All versions of package merge-deep2 are vulnerable to Prototype Pollution via the mergeDeep() function.
CVE-2021-23663CRITICAL9.8All versions of package sey are vulnerable to Prototype Pollution via the deepmerge() function.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now