2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43350CRITICAL9.8An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the P...
CVE-2021-26558HIGH7.5Deserialization of Untrusted Data vulnerability of Apache ShardingSphere-UI allows an attacker to inject outer link reso...
CVE-2021-25980HIGH8.8In Talkyard, versions v0.04.01 through v0.6.74-WIP-63220cb, v0.2020.22-WIP-b2e97fe0e through v0.2021.02-WIP-879ef3fe1 an...
CVE-2021-43397HIGH8.8LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.
CVE-2021-42847CRITICAL9.8Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
CVE-2021-42002CRITICAL9.8Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code exec...
CVE-2021-41833CRITICAL9.8Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
CVE-2021-41081CRITICAL9.8Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search...
CVE-2021-41080CRITICAL9.8Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details sea...
CVE-2021-43573CRITICAL9.8A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processin...
CVE-2021-40873HIGH7.5An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40....
CVE-2021-40872HIGH7.5An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a den...
CVE-2021-40871HIGH7.5An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66. Remote attackers to cause a denial ...
CVE-2021-33816CRITICAL9.8The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mecha...
CVE-2021-33618MEDIUM6.1Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove at...
CVE-2021-42111MEDIUM5.5An issue was discovered in the RCDevs OpenOTP app 1.4.13 and 1.4.14 for iOS. If it is installed on a jailbroken device, ...
CVE-2021-3572MEDIUM5.7A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possi...
CVE-2021-32023HIGH7.8An elevation of privilege vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574...
CVE-2021-32022MEDIUM5.5A low privileged delete vulnerability using CEF RPC server of BlackBerry Protect for Windows version(s) versions 1574 an...
CVE-2021-32021HIGH7.8A denial of service vulnerability in the message broker of BlackBerry Protect for Windows version(s) versions 1574 and e...
CVE-2021-22048HIGH8.8The vCenter Server contains a privilege escalation vulnerability in the IWA (Integrated Windows Authentication) authenti...
CVE-2021-41038MEDIUM6.1In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via po...
CVE-2021-40520CRITICAL9.8Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials.
CVE-2021-40517MEDIUM5.4Airangel HSMX Gateway devices through 5.2.04 is vulnerable to stored Cross Site Scripting. XSS Payload is placed in the ...
CVE-2021-3380MEDIUM6.5Insecure direct object reference (IDOR) vulnerability in ICREM H8 SSRMS allows attackers to disclose sensitive informati...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now