2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40999HIGH7.2A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas...
CVE-2021-42340HIGH7.5The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60...
CVE-2021-38295HIGH7.3In Apache CouchDB, a malicious user with permission to create documents in a database is able to attach a HTML attachmen...
CVE-2021-36389HIGH7.5In Yellowfin before 9.6.1 it is possible to enumerate and download uploaded images through an Insecure Direct Object Ref...
CVE-2021-36388HIGH7.5In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through an Insecure Direct Obj...
CVE-2021-36387MEDIUM5.4In Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploita...
CVE-2021-42369HIGH8.8Imagicle Application Suite (for Cisco UC) before 2021.Summer.2 allows SQL injection. A low-privileged user could inject ...
CVE-2021-32571MEDIUM4.9In OSS-RC systems of the release 18B and older during data migration procedures certain files containing usernames and p...
CVE-2021-42228HIGH8.8A Cross Site Request Forgery (CSRF) vulnerability exists in KindEditor 4.1.x, as demonstrated by examples/uploadbutton.h...
CVE-2021-42227MEDIUM6.1Cross SIte Scripting (XSS) vulnerability exists in KindEditor 4.1.x via a Google search inurl:/examples/uploadbutton.htm...
CVE-2021-32569MEDIUM6.1In OSS-RC systems of the release 18B and older customer documentation browsing libraries under ALEX are subject to Cross...
CVE-2021-41142MEDIUM5.4Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Ther...
CVE-2021-41132MEDIUM6.1OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do ...
CVE-2021-39330Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-24608. Reason: This candidate is a duplicate of ...
CVE-2021-38346HIGH8.8The Brizy Page Builder plugin <= 2.3.11 for WordPress allowed authenticated users to upload executable files to a locati...
CVE-2021-38345MEDIUM6.5The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in u...
CVE-2021-38344MEDIUM5.4The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a s...
CVE-2021-37933HIGH7.5An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, r...
CVE-2021-33179MEDIUM6.1The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scri...
CVE-2021-33178MEDIUM6.5The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path trave...
CVE-2021-33177HIGH8.8The Bulk Modifications functionality in Nagios XI versions prior to 5.8.5 is vulnerable to SQL injection. Exploitation r...
CVE-2021-22964HIGH8.8A redirect vulnerability in the `fastify-static` module version >= 4.2.4 and < 4.4.1 allows remote attackers to redirect...
CVE-2021-22963MEDIUM6.1A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbit...
CVE-2021-20599HIGH7.5Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information vulnerability in MELSEC i...
CVE-2021-3882MEDIUM6.8LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the Led...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now