2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44045HIGH7.8An out-of-bounds write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022....
CVE-2021-44044HIGH7.8An out-of-bounds write vulnerability exists when reading a JPG file using Open Design Alliance Drawings SDK before 2022....
CVE-2021-37253HIGH7.5M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range o...
CVE-2021-4005MEDIUM4.3firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-43415HIGH8.8HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenti...
CVE-2021-35415MEDIUM4.8A stored cross-site scripting (XSS) vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafte...
CVE-2021-35414CRITICAL9.8Chamilo LMS v1.11.x was discovered to contain a SQL injection via the doc parameter in main/plagiarism/compilatio/upload...
CVE-2021-35413HIGH8.8A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated a...
CVE-2021-44349CRITICAL9.8SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameter in App\Manage\Controller\DownloadController.cl...
CVE-2021-44348CRITICAL9.8SQL Injection vulnerability exists in TuziCMS v2.0.6 via the id parameer in App\Manage\Controller\AdvertController.class...
CVE-2021-35346CRITICAL9.8tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function HevcSpsUnit::short_term_ref_pic_...
CVE-2021-35344CRITICAL9.8tsMuxer v2.6.16 was discovered to contain a heap-based buffer overflow via the function BitStreamReader::getCurVal in bi...
CVE-2021-23758CRITICAL9.8All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserial...
CVE-2021-23562HIGH8.8This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An att...
CVE-2021-44352CRITICAL9.8A Stack-based Buffer Overflow vulnerability exists in the Tenda AC15 V15.03.05.18_multi device via the list parameter in...
CVE-2021-44347CRITICAL9.8SQL Injection vulnerability exists in TuziCMS v2.0.6 in App\Manage\Controller\GuestbookController.class.php.
CVE-2021-38909MEDIUM5.4IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2021-29867MEDIUM5.4IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter notebook that they should ...
CVE-2021-29756HIGH8.8IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which cou...
CVE-2021-29719MEDIUM5.3IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a web response specifyin...
CVE-2021-29716MEDIUM6.5IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application that privileged user shou...
CVE-2021-20493MEDIUM6.1IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2021-20470HIGH7.5IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes ...
CVE-2021-43991MEDIUM5.4The Kentico Xperience CMS version 13.0 – 13.0.43 is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability ...
CVE-2021-3980HIGH7.5elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now