2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20526MEDIUM5.3IBM Planning Analytics 2.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set t...
CVE-2021-38379MEDIUM5.5The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
CVE-2021-37221HIGH8.8A file upload vulnerability exists in Sourcecodester Customer Relationship Management System 1.0 via the account update ...
CVE-2021-36756MEDIUM6.5CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
CVE-2021-22101HIGH7.5Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowi...
CVE-2021-41619HIGH7.2An issue was discovered in Gradle Enterprise before 2021.1.2. There is potential remote code execution via the applicati...
CVE-2021-41590MEDIUM5.3In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration ...
CVE-2021-41589CRITICAL9.8In Gradle Enterprise before 2021.3 (and Enterprise Build Cache Node before 10.0), there is potential cache poisoning and...
CVE-2021-41872HIGH7.5Skyworth Digital Technology Penguin Aurora Box 41502 has a denial of service vulnerability, which can be exploited by at...
CVE-2021-34580HIGH7.5In mymbCONNECT24, mbCONNECT24 <= 2.9.0 an unauthenticated user can enumerate valid backend users by checking what kind o...
CVE-2021-38450HIGH8.8The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft...
CVE-2021-37131MEDIUM6.8There is a CSV injection vulnerability in ManageOne, iManager NetEco and iManager NetEco 6000. An attacker with high pri...
CVE-2021-37130HIGH7.5There is a path traversal vulnerability in Huawei FusionCube 6.0.2.The vulnerability is due to that the software uses ex...
CVE-2021-37129HIGH7.5There is an out of bounds write vulnerability in some Huawei products. The vulnerability is caused by a function of a mo...
CVE-2021-37127HIGH7.2There is a signature management vulnerability in some huawei products. An attacker can forge signature and bypass the si...
CVE-2021-37124MEDIUM6.5There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special char...
CVE-2021-37122MEDIUM6.5There is a use-after-free (UAF) vulnerability in Huawei products. An attacker may craft specific packets to exploit this...
CVE-2021-35236MEDIUM5.3The Secure flag is not set in the SSL Cookie of Kiwi Syslog Server 9.7.2 and previous versions. The Secure attribute tel...
CVE-2021-35235MEDIUM5.3The ASP.NET debug feature is enabled by default in Kiwi Syslog Server 9.7.2 and previous versions. ASP.NET allows remote...
CVE-2021-35233MEDIUM5.3The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diag...
CVE-2021-32951MEDIUM5.3WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unautho...
CVE-2021-26610HIGH8.8The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upl...
CVE-2021-41866MEDIUM5.4MyBB before 1.8.28 allows stored XSS because the displayed Template Name value in the Admin CP's theme management is not...
CVE-2021-23877HIGH7.8Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x ma...
CVE-2021-35499MEDIUM5.4The Web Reporting component of TIBCO Software Inc.'s TIBCO Nimbus contains easily exploitable Stored Cross Site Scriptin...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now