2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42115CRITICAL9.1Missing HTTPOnly flag in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27...
CVE-2021-3769CRITICAL9.8# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P`...
CVE-2021-3727CRITICAL9.8# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes fro...
CVE-2021-3726CRITICAL9.8# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` ...
CVE-2021-3725HIGH8.8Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered...
CVE-2021-43790HIGH8.1Lucet is a native WebAssembly compiler and runtime. There is a bug in the main branch of `lucet-runtime` affecting all v...
CVE-2021-44429HIGH7.5Serva 4.4.0 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcod...
CVE-2021-44428HIGH7.5Pinkie 2.15 allows remote attackers to cause a denial of service (daemon crash) via a TFTP read (RRQ) request, aka opcod...
CVE-2021-44427CRITICAL9.8An unauthenticated SQL Injection vulnerability in Rosario Student Information System (aka rosariosis) before 8.1.1 allow...
CVE-2021-43788MEDIUM5Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that...
CVE-2021-43787MEDIUM6.1Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the u...
CVE-2021-43786HIGH7.5Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verific...
CVE-2021-43783HIGH8.5@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a...
CVE-2021-34800HIGH7.5Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before...
CVE-2021-44203MEDIUM5.4Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis ...
CVE-2021-44202MEDIUM5.4Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber P...
CVE-2021-44201MEDIUM6.1Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Prot...
CVE-2021-44200MEDIUM5.4Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect...
CVE-2021-44199MEDIUM5.5DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) b...
CVE-2021-44198HIGH7.8DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (W...
CVE-2021-42365MEDIUM4.8The Asgaros Forums WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the na...
CVE-2021-42364HIGH8.8The Stetic WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the stats_pa...
CVE-2021-42358HIGH8.8The Contact Form With Captcha WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validati...
CVE-2021-43691CRITICAL9.8tripexpress v1.1 is affected by a path manipulation vulnerability in file system/helpers/dompdf/load_font.php. The varia...
CVE-2021-3802MEDIUM4.2A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to ke...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now