2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3709MEDIUM5.5Function check_attachment_for_errors() in file data/general-hooks/ubuntu.py could be tricked into exposing private data ...
CVE-2021-3626HIGH8.8The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket t...
CVE-2021-38675MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Image2PDF. If exploited, this...
CVE-2021-34356MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, ...
CVE-2021-34355MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, thi...
CVE-2021-34354MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, ...
CVE-2021-34352CRITICAL9.8A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ...
CVE-2021-33626HIGH7.8A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently ...
CVE-2021-41324MEDIUM6.5Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enu...
CVE-2021-41101MEDIUM5.7wire-server is an open-source back end for Wire, a secure collaboration platform. Before version 2.106.0, the CORS ` Acc...
CVE-2021-33583CRITICAL9.8REINER timeCard 6.05.07 installs a Microsoft SQL Server with an sa password that is hardcoded in the TCServer.jar file.
CVE-2021-41325MEDIUM6.5Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via ...
CVE-2021-41323MEDIUM6.5Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal...
CVE-2021-41288CRITICAL9.8Zoho ManageEngine OpManager version 125466 and below is vulnerable to SQL Injection in the getReportData API.
CVE-2021-35205MEDIUM5.4NETSCOUT Systems nGeniusONE version 6.3.0 build 1196 allows URL redirection in redirector.
CVE-2021-35204MEDIUM5.4NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Reflected Cross-Site Scripting (XSS) in the support endpoint.
CVE-2021-35203MEDIUM5.7NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the FDSQueryService endpoint.
CVE-2021-35202MEDIUM4.3NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Authorization Bypass (to access an endpoint) in FDSQueryService.
CVE-2021-35201MEDIUM6.5NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.
CVE-2021-35200MEDIUM4.8NETSCOUT nGeniusONE 6.3.0 build 1196 allows high-privileged users to achieve Stored Cross-Site Scripting (XSS) in FDSQue...
CVE-2021-35199MEDIUM5.4NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile.
CVE-2021-35198MEDIUM5.4NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stored Cross-Site Scripting (XSS) in the Packet Analysis module.
CVE-2021-29894HIGH7.5IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 uses weaker than expected cryptographic algorit...
CVE-2021-20578CRITICAL9.8IBM Cloud Pak for Security (CP4S) 1.7.0.0, 1.7.1.0, 1.7.2.0, and 1.8.0.0 could allow an attacker to perform unauthorized...
CVE-2021-20554MEDIUM6.1IBM Sterling Order Management 9.4, 9.5, and 10.0 is vulnerable to cross-site scripting. This vulnerability allows users ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now