2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20042CRITICAL9.8An unauthenticated remote attacker can use SMA 100 as an unintended proxy or intermediary undetectable proxy to bypass f...
CVE-2021-20041HIGH7.5An unauthenticated and remote adversary can consume all of the device's CPU due to crafted HTTP requests sent to SMA100 ...
CVE-2021-20040HIGH7.5A relative path traversal vulnerability in the SMA100 upload funtion allows a remote unauthenticated attacker to upload ...
CVE-2021-20039HIGH8.8Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allo...
CVE-2021-20038CRITICAL9.8A Stack-based buffer overflow vulnerability in SMA100 Apache httpd server's mod_cgi module environment variables allows ...
CVE-2021-44726MEDIUM6.1KNIME Server before 4.13.4 allows XSS via the old WebPortal login page.
CVE-2021-44725HIGH7.5KNIME Server before 4.13.4 allows directory traversal in a request for a client profile.
CVE-2021-41311HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow attackers with access to an administrator account that ...
CVE-2021-41309MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow a user who has had their Jira Service Management access...
CVE-2021-3370MEDIUM6.1DouPHP v1.6 was discovered to contain a cross-site scripting (XSS) vulnerability via /admin/cloud.php.
CVE-2021-44420HIGH7.3In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines cou...
CVE-2021-43808MEDIUM6.1Laravel is a web application framework. Laravel prior to versions 8.75.0, 7.30.6, and 6.20.42 contain a possible cross-s...
CVE-2021-44148MEDIUM6.1GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an a...
CVE-2021-43963HIGH8.1An issue was discovered in Couchbase Sync Gateway 2.7.0 through 2.8.2. The bucket credentials used to read and write dat...
CVE-2021-43810MEDIUM6.1Admidio is a free open source user management system for websites of organizations and groups. A cross-site scripting vu...
CVE-2021-42717HIGH7.5ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thou...
CVE-2021-42567MEDIUM6.1Apereo CAS through 6.4.1 allows XSS via POST requests sent to the REST API endpoints.
CVE-2021-40578HIGH7.2Authenticated Blind & Error-based SQL injection vulnerability was discovered in Online Enrollment Management System in P...
CVE-2021-44149HIGH7.8An issue was discovered in Trusted Firmware OP-TEE Trusted OS through 3.15.0. The OPTEE-OS CSU driver for NXP i.MX6UL So...
CVE-2021-42688HIGH8.8An Integer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x2200...
CVE-2021-42687HIGH8.8A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22005B...
CVE-2021-42686HIGH8.8An Integer Overflow exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B in the Acco...
CVE-2021-42685HIGH8.8An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 . The IOCTL Handler 0x22005B in...
CVE-2021-42683HIGH8.8A Buffer Overflow vulnerability exists in Accops HyWorks Windows Client prior to v 3.2.8.200. The IOCTL Handler 0x22001B...
CVE-2021-42682HIGH8.8An Integer Overflow vulnerability exists in Accops HyWorks DVM Tools prior to v3.3.1.105 .The IOCTL Handler 0x22001B all...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now