2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42342CRITICAL9.8An issue was discovered in GoAhead 4.x and 5.x before 5.1.5. In the file upload filter, user form variables can be passe...
CVE-2021-42341HIGH7.5checkpath in OpenRC before 0.44.7 uses the direct output of strlen() to allocate strings, which does not account for the...
CVE-2021-40854HIGH7.8AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Cha...
CVE-2021-41075CRITICAL9.8The NetFlow Analyzer in Zoho ManageEngine OpManger before 125455 is vulnerable to SQL Injection in the Attacks Module AP...
CVE-2021-40493CRITICAL9.8Zoho ManageEngine OpManager before 125437 is vulnerable to SQL Injection in the support diagnostics module. This occurs ...
CVE-2021-26318MEDIUM4.7A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially...
CVE-2021-42224CRITICAL9.8SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
CVE-2021-42223MEDIUM6.1Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.
CVE-2021-40843HIGH7.3Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An atta...
CVE-2021-40842CRITICAL9.8Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability...
CVE-2021-20131HIGH8.8ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope...
CVE-2021-20130HIGH8.8ManageEngine ADManager Plus Build 7111 contains a post-authentication remote code execution vulnerability due to imprope...
CVE-2021-41139MEDIUM6.1Anuko Time Tracker is an open source, web-based time tracking application written in PHP. When a logged on user selects ...
CVE-2021-40732MEDIUM6.1XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in le...
CVE-2021-35498CRITICAL9.8The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, and TIBCO Product and Servi...
CVE-2021-41138MEDIUM5.3Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pa...
CVE-2021-3057HIGH8.1A stack-based buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect app that enables a man-in-the...
CVE-2021-22036MEDIUM6.5VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. ...
CVE-2021-22035MEDIUM4.3VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interact...
CVE-2021-22033LOW2.7Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability.
CVE-2021-20129HIGH7.5An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to...
CVE-2021-20128MEDIUM5.4The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable...
CVE-2021-20127HIGH8.1An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek...
CVE-2021-20126HIGH8.8Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a we...
CVE-2021-20125CRITICAL9.8An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileSe...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now