2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43803HIGH7.5Next.js is a React framework. In versions of Next.js prior to 12.0.5 or 11.1.3, invalid or malformed URLs could lead to ...
CVE-2021-43802HIGH8.8Etherpad is a real-time collaborative editor. In versions prior to 1.8.16, an attacker can craft an `*.etherpad` file th...
CVE-2021-43982HIGH7.8Delta Electronics CNCSoft Versions 1.01.30 and prior are vulnerable to a stack-based buffer overflow, which may allow an...
CVE-2021-37861HIGH7.5Mattermost 6.0.2 and earlier fails to sufficiently sanitize user's password in audit logs when user creation fails.
CVE-2021-4033MEDIUM6.5kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-44514CRITICAL9.8OpUtils in Zoho ManageEngine OpManager 12.5 before 125490 mishandles authentication for a few audit directories.
CVE-2021-43608CRITICAL9.8Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIM...
CVE-2021-43797MEDIUM6.5Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performan...
CVE-2021-43703CRITICAL9.8An Incorrect Access Control vulnerability exists in zzcms less than or equal to 2019 via admin.php. After disabling Java...
CVE-2021-41265HIGH8.8Flask-AppBuilder is a development framework built on top of Flask. Verions prior to 3.3.4 contain an improper authentica...
CVE-2021-40282HIGH8.8An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, abd 2021 in dl/dl_download.php. when registering ordinary...
CVE-2021-40281HIGH8.8An SQL Injection vulnerability exists in zzcms 8.2, 8.3, 2020, and 2021 in dl/dl_print.php when registering ordinary use...
CVE-2021-39002HIGH7.5IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 uses weaker than expec...
CVE-2021-38951HIGH7.5IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a denial of service, caused by sending a specia...
CVE-2021-38931MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to an information disclos...
CVE-2021-38926MEDIUM5.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a local us...
CVE-2021-29678HIGH8.7IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user wit...
CVE-2021-22568HIGH8.8When using the dart pub publish command to publish a package to a third-party package server, the request would be authe...
CVE-2021-20373HIGH7.5IBM Db2 9.7, 10.1, 10.5, 11.1, and 11.5 may be vulnerable to an Information Disclosure when using the LOAD utility as un...
CVE-2021-4038MEDIUM4.8Cross Site Scripting (XSS) vulnerability in McAfee Network Security Manager (NSM) prior to 10.1 Minor 7 allows a remote ...
CVE-2021-41697MEDIUM6.1A reflected Cross Site Scripting (XSS) vulnerability exists in Premiumdatingscript 4.2.7.7 via the aerror_description pa...
CVE-2021-41696MEDIUM6.5An authentication bypass (account takeover) vulnerability exists in Premiumdatingscript 4.2.7.7 due to a weak password r...
CVE-2021-41695CRITICAL9.8An SQL Injection vulnerability exists in Premiumdatingscript 4.2.7.7 via the ip parameter in connect.php. .
CVE-2021-41694CRITICAL9.8An Incorrect Access Control vulnerability exists in Premiumdatingscript 4.2.7.7 via the password change procedure in req...
CVE-2021-41246HIGH8.8Express OpenID Connect is express JS middleware implementing sign on for Express web apps using OpenID Connect. Versions...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now