2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29735MEDIUM5.4IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability a...
CVE-2021-42770MEDIUM6.1A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the...
CVE-2021-41733MEDIUM6.1Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.
CVE-2021-39182HIGH7.5EnroCrypt is a Python module for encryption and hashing. Prior to version 1.1.4, EnroCrypt used the MD5 hashing algorith...
CVE-2021-28024CRITICAL9.8Unauthorized system access in the login form in ServiceTonic Helpdesk software version < 9.0.35937 allows attacker to lo...
CVE-2021-28023CRITICAL9.8Arbitrary file upload in Service import feature in ServiceTonic Helpdesk software version < 9.0.35937 allows a malicious...
CVE-2021-28022HIGH7.5Blind SQL injection in the login form in ServiceTonic Helpdesk software < 9.0.35937 allows attacker to exfiltrate inform...
CVE-2021-25979CRITICAL9.8Apostrophe CMS versions prior to 3.3.1 did not invalidate existing login sessions when disabling a user account or chang...
CVE-2021-37850MEDIUM5.5ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to ...
CVE-2021-32483MEDIUM5.3Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.
CVE-2021-30132CRITICAL9.8Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges.
CVE-2021-22051MEDIUM6.5Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request...
CVE-2021-32482MEDIUM6.1Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.
CVE-2021-32481MEDIUM6.1Cloudera Hue 4.6.0 allows XSS via the type parameter.
CVE-2021-29994MEDIUM6.1Cloudera Hue 4.6.0 allows XSS.
CVE-2021-29243MEDIUM6.1Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.
CVE-2021-41772HIGH7.5Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing ...
CVE-2021-41771HIGH7.5ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Loc...
CVE-2021-42372HIGH8.8A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticate...
CVE-2021-42371CRITICAL9.8lpar2rrd is a hardcoded system account in XoruX LPAR2RRD and STOR2RRD before 7.30.
CVE-2021-42370HIGH7.5A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is pr...
CVE-2021-42078MEDIUM6.1PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/...
CVE-2021-42077CRITICAL9.8PHP Event Calendar before 2021-09-03 allows SQL injection, as demonstrated by the /server/ajax/user_manager.php username...
CVE-2021-42076HIGH7.5An issue was discovered in Barrier before 2.3.4. An attacker can cause memory exhaustion in the barriers component (aka ...
CVE-2021-42075HIGH7.5An issue was discovered in Barrier before 2.3.4. The barriers component (aka the server-side implementation of Barrier) ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now