2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34415HIGH7.5The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4.6.358.20210205 does not...
CVE-2021-34414HIGH7.2The network proxy page on the web portal for the Zoom on-premise Meeting Connector Controller before version 4.6.348.202...
CVE-2021-34413HIGH7.5All versions of the Zoom Plugin for Microsoft Outlook for MacOS before 5.3.52553.0918 contain a Time-of-check Time-of-us...
CVE-2021-34412HIGH7.8During the installation process for all versions of the Zoom Client for Meetings for Windows before 5.4.0, it is possibl...
CVE-2021-34411HIGH7.8During the installation process forZoom Rooms for Conference Room for Windows before version 5.3.0 it is possible to lau...
CVE-2021-34410HIGH7.8A user-writable application bundle unpacked during the install for all versions of the Zoom Plugin for Microsoft Outlook...
CVE-2021-34409HIGH7.8It was discovered that the installation packages of the Zoom Client for Meetings for MacOS (Standard and for IT Admin) i...
CVE-2021-34408HIGH7.8The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable direct...
CVE-2021-33907CRITICAL9.8The Zoom Client for Meetings for Windows in all versions before 5.3.0 fails to properly validate the certificate informa...
CVE-2021-22272CRITICAL9.4The vulnerability origins in the commissioning process where an attacker of the ControlTouch can enter a serial number i...
CVE-2021-40109MEDIUM6.4A SSRF issue was discovered in Concrete CMS through 8.5.5. Users can access forbidden files on their local network. A us...
CVE-2021-40108HIGH8.8An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on ...
CVE-2021-3828HIGH7.5nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3822HIGH7.5jsoneditor is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3820HIGH7.5inflect is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3819HIGH8.8firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3818MEDIUM5.3grav is vulnerable to Reliance on Cookies without Validation and Integrity Checking
CVE-2021-3799MEDIUM5.4grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames
CVE-2021-23243HIGH7.8In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be...
CVE-2021-40106MEDIUM6.1An issue was discovered in Concrete CMS through 8.5.5. There is unauthenticated stored XSS in blog comments via the webs...
CVE-2021-40105MEDIUM6.1An issue was discovered in Concrete CMS through 8.5.5. There is XSS via Markdown Comments.
CVE-2021-40104HIGH7.5An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
CVE-2021-40103HIGH7.5An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.
CVE-2021-40098CRITICAL9.8An issue was discovered in Concrete CMS through 8.5.5. Path Traversal leading to RCE via external form by adding a regul...
CVE-2021-40097HIGH8.8An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution vi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now