2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41565MEDIUM6.1TadTools special page parameter does not properly restrict the input of specific characters, thus remote attackers can i...
CVE-2021-41564MEDIUM6.5Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parame...
CVE-2021-41563MEDIUM6.1Tad Book3 editing book function does not filter special characters. Unauthenticated attackers can remotely inject JavaSc...
CVE-2021-3312MEDIUM6.5An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users ...
CVE-2021-36767CRITICAL9.8In Digi RealPort through 4.10.490, authentication relies on a challenge-response mechanism that gives access to the serv...
CVE-2021-35979HIGH8.1An issue was discovered in Digi RealPort through 4.8.488.0. The 'encrypted' mode is vulnerable to man-in-the-middle atta...
CVE-2021-35977CRITICAL9.8An issue was discovered in Digi RealPort for Windows through 4.8.488.0. A buffer overflow exists in the handling of ADDP...
CVE-2021-41133HIGH7.8Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior t...
CVE-2021-41947HIGH7.2A SQL injection vulnerability exists in Subrion CMS v4.2.1 in the visual-mode.
CVE-2021-40832MEDIUM6.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component u...
CVE-2021-33603MEDIUM6.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in ce...
CVE-2021-25271MEDIUM6A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318...
CVE-2021-25270MEDIUM6.7A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.
CVE-2021-41115MEDIUM6.5Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to c...
CVE-2021-38298CRITICAL9.8Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
CVE-2021-42095HIGH7.5Xshell before 7.0.0.76 allows attackers to cause a crash by triggering rapid changes to the title bar.
CVE-2021-42091CRITICAL9.1An issue was discovered in Zammad before 4.1.1. SSRF can occur via GitHub or GitLab integration.
CVE-2021-42090CRITICAL9.8An issue was discovered in Zammad before 4.1.1. The Form functionality allows remote code execution because deserializat...
CVE-2021-42089HIGH7.5An issue was discovered in Zammad before 4.1.1. The REST API discloses sensitive information.
CVE-2021-42088MEDIUM6.1An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.
CVE-2021-42087MEDIUM4.9An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
CVE-2021-42086HIGH8.8An issue was discovered in Zammad before 4.1.1. An Agent account can modify account data, and gain admin access, via a c...
CVE-2021-42085MEDIUM5.4An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
CVE-2021-42084MEDIUM6.5An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted re...
CVE-2021-42094CRITICAL9.8An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now