2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38283HIGH7.5Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read application log files containing se...
CVE-2021-38147HIGH7.5Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to download arbitrary files, such as report...
CVE-2021-21707MEDIUM5.3In PHP versions 7.3.x below 7.3.33, 7.4.x below 7.4.26 and 8.0.x below 8.0.13, certain XML parsing functions, like simpl...
CVE-2021-44077CRITICAL9.8Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before 11014 ...
CVE-2021-32061MEDIUM5.3S3Scanner before 2.0.2 allows Directory Traversal via a crafted bucket, as demonstrated by a <Key>../ substring in a Lis...
CVE-2021-44094HIGH7.8ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could execute any JAR file
CVE-2021-44093CRITICAL9.8A Remote Command Execution vulnerability on the background in zrlog 2.2.2, at the upload avatar function, could bypass t...
CVE-2021-4020MEDIUM5.4janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-23654CRITICAL9.8This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted with...
CVE-2021-43785MEDIUM6.1@joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for ...
CVE-2021-43776MEDIUM6.1Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a mali...
CVE-2021-41279HIGH8.8BaserCMS is an open source content management system with a focus on Japanese language support. In affected versions use...
CVE-2021-41243HIGH8.8There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS....
CVE-2021-40833MEDIUM5.5A vulnerability affecting F-Secure antivirus engine was discovered whereby unpacking UPX file can lead to denial-of-serv...
CVE-2021-36919MEDIUM5.4Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (version...
CVE-2021-36843MEDIUM4.8Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress Floating Social Media Icon plugin ...
CVE-2021-35533HIGH7.5Improper Input Validation vulnerability in the APDU parser in the Bidirectional Communication Interface (BCI) IEC 60870-...
CVE-2021-26615HIGH8.8ARK library allows attackers to execute remote code via the parameter(path value) of Ark_NormalizeAndDupPAthNameW functi...
CVE-2021-26611CRITICAL9.8HejHome GKW-IC052 IP Camera contained a hard-coded credentials vulnerability. This issue allows remote attackers to oper...
CVE-2021-36807HIGH8.8An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before versi...
CVE-2021-25269MEDIUM4.4A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service p...
CVE-2021-38686HIGH8.8An improper authentication vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerabil...
CVE-2021-38685CRITICAL9.8A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability all...
CVE-2021-44225MEDIUM5.4In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user ...
CVE-2021-44223CRITICAL9.8WordPress before 5.8 lacks support for the Update URI plugin header. This makes it easier for remote attackers to execut...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now