2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41027HIGH7.8A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute ...
CVE-2021-41024HIGH7.5A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may al...
CVE-2021-41015MEDIUM6.1A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4....
CVE-2021-41014HIGH7.5A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthentic...
CVE-2021-36191MEDIUM5.4A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below all...
CVE-2021-26109CRITICAL9.8An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an u...
CVE-2021-26108HIGH7.5A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retri...
CVE-2021-44557CRITICAL9.1National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External ...
CVE-2021-44556CRITICAL9.1National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Enti...
CVE-2021-43067MEDIUM6.5A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2...
CVE-2021-42760HIGH8.8A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6....
CVE-2021-42752MEDIUM5.4A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6....
CVE-2021-41029MEDIUM5.4A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6....
CVE-2021-32591MEDIUM5.3A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSan...
CVE-2021-26103HIGH8.8An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2....
CVE-2021-4050MEDIUM6.1livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-42758HIGH8.8An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote att...
CVE-2021-42757MEDIUM6.7A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allo...
CVE-2021-36180HIGH8.8Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management i...
CVE-2021-31850MEDIUM6.1A denial-of-service vulnerability in Database Security (DBS) prior to 4.8.4 allows a remote authenticated administrator ...
CVE-2021-26110HIGH7.8An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0....
CVE-2021-20047HIGH7.8SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerabili...
CVE-2021-20045CRITICAL9.8A buffer overflow vulnerability in SMA100 sonicfiles RAC_COPY_TO (RacNumber 36) method allows a remote unauthenticated a...
CVE-2021-20044HIGH8.8A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker ...
CVE-2021-20043HIGH8.8A Heap-based buffer overflow vulnerability in SonicWall SMA100 getBookmarks method allows a remote authenticated attacke...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now