2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42093HIGH7.2An issue was discovered in Zammad before 4.1.1. An admin can execute code on the server via a crafted request that manip...
CVE-2021-42092MEDIUM5.4An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to ...
CVE-2021-41130MEDIUM5.4Extensible Service Proxy, a.k.a. ESP is a proxy which enables API management capabilities for JSON/REST or gRPC API serv...
CVE-2021-29700MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sen...
CVE-2021-20584HIGH7.5IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote attacker to upload arbitrary files, caused by imp...
CVE-2021-20571MEDIUM5.4IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability all...
CVE-2021-20561MEDIUM6.1IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-20552MEDIUM4.3IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a d...
CVE-2021-20489HIGH8.8IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site request forgery which could allow an attac...
CVE-2021-20481MEDIUM6.1IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-20473MEDIUM6.5IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could al...
CVE-2021-20376MEDIUM4.3IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to th...
CVE-2021-20375MEDIUM6.5IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message s...
CVE-2021-20372MEDIUM4.3IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow a remote authenticated user to cause a denial of another u...
CVE-2021-42071CRITICAL9.8In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac...
CVE-2021-23447MEDIUM6.1This affects the package teddy before 0.5.9. A type confusion vulnerability can be used to bypass input sanitization whe...
CVE-2021-42013CRITICAL9.8It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path...
CVE-2021-40726HIGH7.8Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a...
CVE-2021-40725HIGH7.8Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a...
CVE-2021-40439MEDIUM6.5Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion L...
CVE-2021-3834MEDIUM6.1Integria IMS in its 5.0.92 version does not filter correctly some fields related to the login.php file. An attacker coul...
CVE-2021-3833CRITICAL9.8Integria IMS login check uses a loose comparator ("==") to compare the MD5 hash of the password provided by the user and...
CVE-2021-37931CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37930CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37929CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now