2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39831HIGH7.8Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-...
CVE-2021-39830HIGH7.8Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by a memory c...
CVE-2021-39829HIGH7.8Adobe Framemaker versions 2019 Update 8 (and earlier) and 2020 Release Update 2 (and earlier) are affected by an out-of-...
CVE-2021-39821HIGH7.8Adobe InDesign versions 16.3 (and earlier), and 16.3.1 (and earlier) are affected by an out-of-bounds read vulnerability...
CVE-2021-35982HIGH7.3Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) a...
CVE-2021-29834MEDIUM5.4IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3,20.0.0.1, 20.0.0.2, and 21.0...
CVE-2021-28547HIGH7.8Adobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulne...
CVE-2021-25962HIGH8.8“Shuup” application in versions 0.4.2 to 2.10.8 is affected by the “Formula Injection” vulnerability. A customer can inj...
CVE-2021-25961HIGH8In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password ...
CVE-2021-25960HIGH8In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulne...
CVE-2021-25959MEDIUM6.1In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized pa...
CVE-2021-40651MEDIUM6.5OS4Ed OpenSIS Community 8.0 is vulnerable to a local file inclusion vulnerability in Modules.php (modname parameter), wh...
CVE-2021-36745CRITICAL9.8A vulnerability in Trend Micro ServerProtect for Storage 6.0, ServerProtect for EMC Celerra 5.8, ServerProtect for Netwo...
CVE-2021-35028HIGH7.8A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticat...
CVE-2021-35027HIGH7.5A directory traversal vulnerability in the web server of the Zyxel VPN2S firmware version 1.12 could allow a remote atta...
CVE-2021-32466HIGH7An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks versio...
CVE-2021-33924CRITICAL9.8Confluent Ansible (cp-ansible) version 5.5.0, 5.5.1, 5.5.2 and 6.0.0 is vulnerable to Incorrect Access Control via its a...
CVE-2021-33923MEDIUM5.5Insecure permissions in Confluent Ansible (cp-ansible) 5.5.0, 5.5.1, 5.5.2 and 6.0.0 allows local attackers to access so...
CVE-2021-41106LOW3.3JWT is a library to work with JSON Web Token and JSON Web Signature. Prior to versions 3.4.6, 4.0.4, and 4.1.5, users of...
CVE-2021-36297HIGH7.8SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load a...
CVE-2021-36286HIGH7.1Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deleti...
CVE-2021-36285MEDIUM4.4Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated mal...
CVE-2021-36284MEDIUM4.4Dell BIOS contains an Improper Restriction of Excessive Authentication Attempts vulnerability. A local authenticated mal...
CVE-2021-36283MEDIUM6.7Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...
CVE-2021-21570MEDIUM4.9Dell NetWorker, versions 18.x and 19.x contain an Information disclosure vulnerability. A NetWorker server user with rem...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now