2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43676CRITICAL9.8matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.
CVE-2021-44278CRITICAL9.8Librenms 21.11.0 is affected by a path manipulation vulnerability in includes/html/pages/device/showconfig.inc.php.
CVE-2021-43674CRITICAL9.8ThinkUp 2.0-beta.10 is affected by a path manipulation vulnerability in Smarty.class.php. NOTE: This vulnerability only ...
CVE-2021-43673MEDIUM6.1dzzoffice 2.02.1_SC_UTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of th...
CVE-2021-4000MEDIUM6.1showdoc is vulnerable to URL Redirection to Untrusted Site
CVE-2021-44022MEDIUM5.5A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected ins...
CVE-2021-44021HIGH7.8An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker...
CVE-2021-44020HIGH7.8An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker...
CVE-2021-44019HIGH7.8An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker...
CVE-2021-43772MEDIUM5.5Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be ...
CVE-2021-25785MEDIUM4.8Taocms v2.5Beta5 was discovered to contain a cross-site scripting (XSS) vulnerability via the component Management colum...
CVE-2021-25784HIGH7.2Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article.
CVE-2021-25783HIGH7.2Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search.
CVE-2021-28237CRITICAL9.8LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
CVE-2021-28236HIGH7.5LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.
CVE-2021-43327MEDIUM4.6An issue was discovered on Renesas RX65 and RX65N devices. With a VCC glitch, an attacker can extract the security ID ke...
CVE-2021-44050MEDIUM6.5CA Network Flow Analysis (NFA) 21.2.1 and earlier contain a SQL injection vulnerability in the NFA web application, due ...
CVE-2021-40334HIGH7.5Missing Handler vulnerability in the proprietary management protocol (port TCP 5558) of Hitachi Energy FOX61x, XCM20 all...
CVE-2021-40333HIGH7.1Weak Password Requirements vulnerability in Hitachi Energy FOX61x, XCM20 allows an attacker to gain unauthorized access ...
CVE-2021-43795HIGH7.5Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local ...
CVE-2021-44518MEDIUM6.8An issue was discovered in the eGeeTouch 3rd Generation Travel Padlock application for Android. The lock sends a pairing...
CVE-2021-3944MEDIUM6.8bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-23264CRITICAL9.1Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete...
CVE-2021-23263HIGH7.5Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and so...
CVE-2021-23262HIGH7.2Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now