2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43282MEDIUM6.5An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone with...
CVE-2021-42099CRITICAL9.8Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
CVE-2021-26612CRITICAL9.8An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remot...
CVE-2021-22095MEDIUM6.5In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, wil...
CVE-2021-39000MEDIUM5.5IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local attacker to obtain sensitive information by inclusion of sensiti...
CVE-2021-38999MEDIUM5.5IBM MQ Appliance could allow a local attacker to obtain sensitive information by inclusion of sensitive data within trac...
CVE-2021-38967MEDIUM6.7IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Forc...
CVE-2021-38958MEDIUM5.5IBM MQ Appliance 9.2 CD and 9.2 LTS is affected by a denial of service attack caused by a concurrency issue. IBM X-Force...
CVE-2021-43202CRITICAL9.8In JetBrains TeamCity before 2021.1.3, the X-Frame-Options header is missing in some cases.
CVE-2021-43998MEDIUM6.5HashiCorp Vault and Vault Enterprise 0.11.0 up to 1.7.5 and 1.8.4 templated ACL policies would always match the first-cr...
CVE-2021-41679CRITICAL9.8A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database...
CVE-2021-41678CRITICAL9.8A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database...
CVE-2021-25987MEDIUM4.6Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious java...
CVE-2021-41677CRITICAL9.8A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database...
CVE-2021-43771HIGH7.8Trend Micro Antivirus for Mac 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulne...
CVE-2021-42545CRITICAL9.1An insufficient session expiration vulnerability exists in Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7....
CVE-2021-42544CRITICAL9.8Missing Rate Limiting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27...
CVE-2021-42123HIGH8.8Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1...
CVE-2021-42122MEDIUM4.3Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <...
CVE-2021-42121MEDIUM4.3Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <...
CVE-2021-42120MEDIUM6.5Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <...
CVE-2021-42119MEDIUM5.4Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version...
CVE-2021-42118MEDIUM5.4Persistent Cross Site Scripting in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version...
CVE-2021-42117MEDIUM5.4Insufficient Input Validation in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <...
CVE-2021-42116MEDIUM4.3Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now