2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24017MEDIUM4.3An improper authentication in Fortinet FortiManager version 6.4.3 and below, 6.2.6 and below allows attacker to assign a...
CVE-2021-24016MEDIUM6.3An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and...
CVE-2021-41109HIGH7.5Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2021-21089LOW3.3Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e...
CVE-2021-41720Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-41729CRITICAL9.1BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrar...
CVE-2021-41302HIGH7.3ECOA BAS controller stores sensitive data (backup exports) in clear-text, thus the unauthenticated attacker can remotely...
CVE-2021-41301CRITICAL9.8ECOA BAS controller is vulnerable to configuration disclosure when direct object reference is made to the specific files...
CVE-2021-41300CRITICAL9.8ECOA BAS controller’s special page displays user account and passwords in plain text, thus unauthenticated attackers can...
CVE-2021-41299CRITICAL9.8ECOA BAS controller is vulnerable to hard-coded credentials within its Linux distribution image, thus remote attackers c...
CVE-2021-41298HIGH8.8ECOA BAS controller is vulnerable to insecure direct object references that occur when the application provides direct a...
CVE-2021-41297HIGH8.8ECOA BAS controller is vulnerable to weak access control mechanism allowing authenticated user to remotely escalate priv...
CVE-2021-41296CRITICAL9.8ECOA BAS controller uses weak set of default administrative credentials that can be easily guessed in remote password at...
CVE-2021-41295HIGH8.8ECOA BAS controller has a Cross-Site Request Forgery vulnerability, thus authenticated attacker can remotely place a for...
CVE-2021-41294CRITICAL9.1ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files deletion. Using the specific GE...
CVE-2021-41293HIGH7.5ECOA BAS controller suffers from a path traversal vulnerability, causing arbitrary files disclosure. Using the specific ...
CVE-2021-41292CRITICAL9.1ECOA BAS controller suffers from an authentication bypass vulnerability. An unauthenticated attacker through cookie pois...
CVE-2021-41291HIGH7.5ECOA BAS controller suffers from a path traversal content disclosure vulnerability. Using the GET parameter in File Mana...
CVE-2021-41290CRITICAL9.8ECOA BAS controller suffers from an arbitrary file write and path traversal vulnerability. Using the POST parameters, un...
CVE-2021-41616CRITICAL9.8Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL ...
CVE-2021-25963MEDIUM6.1In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of ...
CVE-2021-41829HIGH7.5Zoho ManageEngine Remote Access Plus before 10.1.2121.1 relies on the application's build number to calculate a certain ...
CVE-2021-41828HIGH7.5Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials associated with resetPWD.xml.
CVE-2021-41827HIGH7.5Zoho ManageEngine Remote Access Plus before 10.1.2121.1 has hardcoded credentials for read-only access. The credentials ...
CVE-2021-41826MEDIUM6.1PlaceOS Authentication Service before 1.29.10.0 allows app/controllers/auth/sessions_controller.rb open redirect.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now