2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38466MEDIUM6.1InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not perform sufficient input validation on client...
CVE-2021-38464HIGH7.4InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have inadequate encryption strength, which may allow...
CVE-2021-38462CRITICAL9.8InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This ...
CVE-2021-42261HIGH7.5Revisor Video Management System (VMS) before 2.0.0 has a directory traversal vulnerability. Successful exploitation coul...
CVE-2021-36512HIGH7.5An issue was discovered in function scanallsubs in src/sbbs3/scansubs.cpp in Synchronet BBS, which may allow attackers t...
CVE-2021-25968MEDIUM5.4In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged applicatio...
CVE-2021-20836MEDIUM6.5Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privile...
CVE-2021-41155HIGH8.8Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi...
CVE-2021-41154HIGH8.8Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In affected versi...
CVE-2021-42650MEDIUM6.1Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
CVE-2021-41156MEDIUM5.4anuko/timetracker is an, open source time tracking system. In affected versions Time Tracker uses browser_today hidden c...
CVE-2021-41153CRITICAL9.8The evm crate is a pure Rust implementation of Ethereum Virtual Machine. In `evm` crate `< 0.31.0`, `JUMPI` opcode's con...
CVE-2021-41152HIGH7.7OpenOlat is a web-based e-learning platform for teaching, learning, assessment and communication, an LMS, a learning man...
CVE-2021-41151MEDIUM4.9Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitiv...
CVE-2021-42055MEDIUM6.8ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically...
CVE-2021-36513HIGH7.5An issue was discovered in function sofia_handle_sip_i_notify in sofia.c in SignalWire freeswitch before 1.10.6, may all...
CVE-2021-29878MEDIUM5.4IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2021-23449CRITICAL10This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitr...
CVE-2021-42576CRITICAL9.8The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce ...
CVE-2021-42575CRITICAL9.8The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, an...
CVE-2021-41971HIGH8.8Apache Superset up to and including 1.3.0 when configured with ENABLE_TEMPLATE_PROCESSING on (disabled by default) allow...
CVE-2021-32609MEDIUM5.4Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker ...
CVE-2021-42098HIGH8.8An incomplete permission check on entries in Devolutions Remote Desktop Manager before 2021.2.16 allows attackers to byp...
CVE-2021-41991HIGH7.5The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests wi...
CVE-2021-41990HIGH7.5The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS sig...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now