2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37928CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37926CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37924CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37923CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37922MEDIUM5.3Zoho ManageEngine ADManager Plus version 7110 and prior is vulnerable to path traversal which allows copying of files fr...
CVE-2021-37921CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37920CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37919CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37918CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file upload which leads to remote code execu...
CVE-2021-37762CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows unrestricted file overwrite leading to remote code execut...
CVE-2021-28129HIGH7.8While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but ins...
CVE-2021-41794HIGH7.5ogs_fqdn_parse in Open5GS 1.0.0 through 2.3.3 inappropriately trusts a client-supplied length value, leading to a buffer...
CVE-2021-35067HIGH8.1Meross MSG100 devices before 3.2.3 allow an attacker to replay the same data or similar data (e.g., an attacker who snif...
CVE-2021-33903HIGH8.8In LCOS 10.40 to 10.42.0473-RU3 with SNMPv3 enabled on LANCOM devices, changing the password of the root user via the CL...
CVE-2021-28661MEDIUM4.3Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by que...
CVE-2021-41865MEDIUM6.5HashiCorp Nomad and Nomad Enterprise 1.1.1 through 1.1.5 allowed authenticated users with job submission capabilities to...
CVE-2021-40978HIGH7.5The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obt...
CVE-2021-3832CRITICAL9.8Integria IMS in its 5.0.92 version is vulnerable to a Remote Code Execution attack through file uploading. An unauthenti...
CVE-2021-36150MEDIUM6.1SilverStripe Framework through 4.8.1 allows XSS.
CVE-2021-22958CRITICAL9.8A Server-Side Request Forgery vulnerability was found in concrete5 < 8.5.5 that allowed a decimal notation encoded IP ad...
CVE-2021-22930CRITICAL9.8Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to ...
CVE-2021-20605Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-20604Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-20603Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-20602Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now