2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23639CRITICAL9.8The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matte...
CVE-2021-23561CRITICAL9.8All versions of package comb are vulnerable to Prototype Pollution via the deepMerge() function.
CVE-2021-23463CRITICAL9.1The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via ...
CVE-2021-31747MEDIUM4.8Missing SSL Certificate Validation issue exists in Pluck 4.7.15 in update_applet.php, which could lead to man-in-the-mid...
CVE-2021-27984HIGH8.1In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
CVE-2021-27983CRITICAL9.8Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
CVE-2021-43813MEDIUM4.3Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains...
CVE-2021-38937MEDIUM6.5IBM PowerVM Hypervisor FW940, FW950, and FW1010 could allow an authenticated user to cause the system to crash using a s...
CVE-2021-38917CRITICAL9.1IBM PowerVM Hypervisor FW860, FW940, and FW950 could allow an attacker that gains service access to the FSP can read and...
CVE-2021-31746CRITICAL9.8Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in ...
CVE-2021-31745HIGH7.5Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to sustain unauthorized access ...
CVE-2021-37935HIGH7.5An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenti...
CVE-2021-37934CRITICAL9.8Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterpris...
CVE-2021-36911MEDIUM5.4Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Comment Engine Pro plugin (versions <= 1.0), cou...
CVE-2021-29214HIGH7.2A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administr...
CVE-2021-3829MEDIUM6.1openwhyd is vulnerable to URL Redirection to Untrusted Site
CVE-2021-40834MEDIUM4.3A user interface overlay vulnerability was discovered in F-secure SAFE Browser for Android. When user click on a special...
CVE-2021-37189HIGH7.5An issue was discovered on Digi TransPort Gateway devices through 5.2.13.4. They do not set the Secure attribute for sen...
CVE-2021-37188HIGH8.8An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may load customized firm...
CVE-2021-37187MEDIUM6.5An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file...
CVE-2021-35978CRITICAL9.8An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command exe...
CVE-2021-4084MEDIUM6.1pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4082MEDIUM4.3pimcore is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4081MEDIUM6.1pimcore is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-44228CRITICAL10Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in con...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now