2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44219CRITICAL9.8Gin-Vue-Admin before 2.4.6 mishandles a SQL database.
CVE-2021-43778HIGH7.5Barcode is a GLPI plugin for printing barcodes and QR codes. GLPI instances version 2.x prior to version 2.6.1 with the ...
CVE-2021-41270MEDIUM6.5Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and consol...
CVE-2021-41268HIGH8.8Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of...
CVE-2021-41267MEDIUM6.5Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set...
CVE-2021-22957HIGH8.8A Cross-Origin Resource Sharing (CORS) vulnerability found in UniFi Protect application Version 1.19.2 and earlier allow...
CVE-2021-43268MEDIUM6.5An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to readin...
CVE-2021-38873HIGH7.8IBM Planning Analytics 2.0 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary command...
CVE-2021-36917HIGH7.5WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrie...
CVE-2021-36916CRITICAL9.8The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP...
CVE-2021-34424HIGH7.5A vulnerability was discovered in the Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before vers...
CVE-2021-34423CRITICAL9.8A buffer overflow vulnerability was discovered in Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows)...
CVE-2021-22049CRITICAL9.8The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client ...
CVE-2021-21980HIGH7.5The vSphere Web Client (FLEX/Flash) contains an unauthorized arbitrary file read vulnerability. A malicious actor with n...
CVE-2021-43780HIGH8.8Redash is a package for data visualization and sharing. In versions 10.0 and priorm the implementation of URL-loading da...
CVE-2021-43777MEDIUM6.1Redash is a package for data visualization and sharing. In Redash version 10.0 and prior, the implementation of Google L...
CVE-2021-41192MEDIUM6.5Redash is a package for data visualization and sharing. If an admin sets up Redash versions 10.0.0 and prior without exp...
CVE-2021-3554CRITICAL10Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender Endpoint Security Tools for...
CVE-2021-3553HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService of Bitdefender Endpoint Security Tools allows...
CVE-2021-3552HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability in the EPPUpdateService component of Bitdefender Endpoint Security To...
CVE-2021-32037MEDIUM6.5An authorized user may trigger an invariant which may result in denial of service or server exit if a relevant aggregati...
CVE-2021-31822HIGH7.8When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. ...
CVE-2021-20850CRITICAL9.8PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2 ...
CVE-2021-20848MEDIUM6.1Cross-site scripting vulnerability in rwtxt versions prior to v1.8.6 allows a remote attacker to inject an arbitrary scr...
CVE-2021-20846HIGH8.8Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allow...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now