2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-41938HIGH7.2An issue was discovered in ShopXO CMS 2.2.0. After entering the management page, there is an arbitrary file upload vulne...
CVE-2021-42704HIGH7.8Inkscape version 0.91 is vulnerable to an out-of-bounds write, which may allow an attacker to arbitrary execute code.
CVE-2021-42852HIGH8A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authent...
CVE-2021-42850HIGH7.8A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud S...
CVE-2021-3969HIGH7A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System I...
CVE-2021-3922HIGH7A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation,...
CVE-2021-38872HIGH7.5IBM DataPower Gateway 10.0.2.0, 10.0.3.0, 10.0.1.0 through 10.0.1.4, and 2018.4.1.0 through 2018.4.1.17 could allow a re...
CVE-2021-42643HIGH8.8cmseasy V7.7.5_20211012 is affected by an arbitrary file write vulnerability. Through this vulnerability, a PHP script f...
CVE-2021-33025HIGH7.8xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.
CVE-2021-23267HIGH8.8Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticat...
CVE-2021-25119HIGH7.2The AGIL WordPress plugin through 1.0 accepts all zip files and automatically extracts the zip file without validating t...
CVE-2021-42870HIGH7.5ACCEL-PPP 1.12.0 has an out-of-bounds read in post_msg when processing a call_clear_request.
CVE-2021-41965HIGH8.8A SQL injection vulnerability exists in ChurchCRM version 2.0.0 to 4.4.5 that allows an authenticated attacker to issue ...
CVE-2021-33013HIGH7.5mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information.
CVE-2021-33009HIGH7.5mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file s...
CVE-2021-33005HIGH7.5mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary ...
CVE-2021-27505HIGH7.5mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing informa...
CVE-2021-46789HIGH7.5Configuration defects in the secure OS module. Successful exploitation of this vulnerability can affect availability.
CVE-2021-46788HIGH7.5Third-party pop-up window coverage vulnerability in the iConnect module.Successful exploitation of this vulnerability ma...
CVE-2021-46787HIGH7.5The AMS module has a vulnerability of improper permission control.Successful exploitation of this vulnerability may caus...
CVE-2021-22275HIGH8.6Buffer Overflow vulnerability in B&R Automation Runtime webserver allows an unauthenticated network-based attacker to st...
CVE-2021-42969HIGH8.8Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a ...
CVE-2021-27777HIGH7.5XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input...
CVE-2021-27771HIGH7.6User SID can be modified resulting in an Arbitrary File Upload or deletion of directories causing a Denial of Service. W...
CVE-2021-27770HIGH8.8The vulnerability was discovered within the “FaviconService”. The service takes a base64-encoded URL which is then reque...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now