2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43272CRITICAL9.8An improper handling of exceptional conditions vulnerability exists in Open Design Alliance ODA Viewer sample before 202...
CVE-2021-41057HIGH7.1In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file withou...
CVE-2021-26795HIGH8.8A SQL Injection vulnerability in /appliance/shiftmgn.php in TalariaX sendQuick Alert Plus Server Admin 4.3 before 8HF11 ...
CVE-2021-43617CRITICAL9.8Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val...
CVE-2021-43616CRITICAL9.8The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in pack...
CVE-2021-41653CRITICAL9.8The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to r...
CVE-2021-3915MEDIUM5.7bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2021-3776MEDIUM5.4showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3775MEDIUM5.4showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3683MEDIUM6.5showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3945MEDIUM6.1django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3938MEDIUM5.4snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3932MEDIUM4.3twill is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3931MEDIUM4.3snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3921MEDIUM4.3firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3918CRITICAL9.8json-schema is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-38684CRITICAL9.8A stack buffer overflow vulnerability has been reported to affect QNAP NAS running Multimedia Console. If exploited, thi...
CVE-2021-34357MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, thi...
CVE-2021-41229MEDIUM6.5BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which...
CVE-2021-36325MEDIUM6.7Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2021-36324MEDIUM6.7Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2021-36323MEDIUM6.7Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2021-36315MEDIUM6.8Dell EMC PowerScale Nodes contain a hardware design flaw. This may allow a local unauthenticated user to escalate privil...
CVE-2021-36305MEDIUM6.5Dell PowerScale OneFS contains an Unsynchronized Access to Shared Data in a Multithreaded Context in SMB CA handling. An...
CVE-2021-21528HIGH7.5Dell EMC PowerScale OneFS versions 9.1.0, 9.2.0.x, 9.2.1.x contain an Exposure of Information through Directory Listing ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now