2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38948CRITICAL9.1IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XM...
CVE-2021-29888HIGH8.8IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to exec...
CVE-2021-29875HIGH7.5IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information due to a insecure third p...
CVE-2021-29771MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2021-29738MEDIUM5.4IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery...
CVE-2021-29737HIGH7.5IBM InfoSphere Data Flow Designer Engine (IBM InfoSphere Information Server 11.7 ) component has improper validation of ...
CVE-2021-36794CRITICAL9.8In Siren Investigate before 11.1.4, when enabling the cluster feature of the Siren Alert application, TLS verifications ...
CVE-2021-42568MEDIUM4.3Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function vi...
CVE-2021-36925HIGH7.8RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users ...
CVE-2021-36924HIGH7.8RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users ...
CVE-2021-36923HIGH7.8RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users ...
CVE-2021-36922HIGH7.8RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users ...
CVE-2021-42763HIGH7.5Couchbase Server before 6.6.3 and 7.x before 7.0.2 stores Sensitive Information in Cleartext. The issue occurs when the ...
CVE-2021-37842HIGH7.5metakv in Couchbase Server 7.0.0 uses Cleartext for Storage of Sensitive Information. Remote Cluster XDCR credentials ca...
CVE-2021-27723Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-27722MEDIUM5.5An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data ...
CVE-2021-36560CRITICAL9.8Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to...
CVE-2021-33611MEDIUM6.1Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2...
CVE-2021-3765HIGH7.5validator.js is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-33593MEDIUM5.3Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the ad...
CVE-2021-25973MEDIUM6.5In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even whe...
CVE-2021-41310MEDIUM6.1Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or ...
CVE-2021-43058MEDIUM6.1An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exp...
CVE-2021-41187HIGH8.8DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection s...
CVE-2021-39346MEDIUM4.8The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now