2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36306CRITICAL9.8Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains an authentication bypass vulnerabili...
CVE-2021-38681MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Ragic Cloud DB. If exp...
CVE-2021-34358HIGH8.8We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and la...
CVE-2021-39198MEDIUM5.4OroCRM is an open source Client Relationship Management (CRM) application. Affected versions we found to suffer from a v...
CVE-2021-41280CRITICAL9.8Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is pos...
CVE-2021-23433CRITICAL9.8The package algoliasearch-helper before 3.6.2 are vulnerable to Prototype Pollution due to use of the merge function in ...
CVE-2021-21898HIGH8.8A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-...
CVE-2021-44038HIGH7.8An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (w...
CVE-2021-43555HIGH7.8mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may ...
CVE-2021-42744MEDIUM5.5Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource fr...
CVE-2021-42254HIGH7.8BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions...
CVE-2021-40391CRITICAL9.8An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (co...
CVE-2021-36884MEDIUM5.4Authenticated Persistent Cross-Site Scripting (XSS) vulnerability discovered in WordPress Backup Migration plugin <= 1.1...
CVE-2021-26262MEDIUM5.5Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource fr...
CVE-2021-26248MEDIUM5.5Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource fr...
CVE-2021-22970HIGH7.5Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system...
CVE-2021-22969MEDIUM5.3Concrete CMS (formerly concrete5) versions below 8.5.7 has a SSRF mitigation bypass using DNS Rebind attack giving an at...
CVE-2021-22968HIGH7.2A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Co...
CVE-2021-22967HIGH7.5In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowe...
CVE-2021-22966HIGH8.8Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "...
CVE-2021-22965HIGH7.5A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial ...
CVE-2021-22951HIGH7.5Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) p...
CVE-2021-21900HIGH8.8A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f...
CVE-2021-21899HIGH8.8A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2...
CVE-2021-41569HIGH7.5SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the app...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now