2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20377LOW2.7IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error...
CVE-2021-41428Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-41381HIGH7.5Payara Micro Community 5.2021.6 and below allows Directory Traversal.
CVE-2021-3824MEDIUM6.1OpenVPN Access Server 2.9.0 through 2.9.4 allow remote attackers to inject arbitrary web script or HTML via the web logi...
CVE-2021-36872MEDIUM5.4Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in WordPress Popular Posts plugin (versions <= 5.3.3)....
CVE-2021-26750HIGH7.8DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to...
CVE-2021-21913CRITICAL9.8An information disclosure vulnerability exists in the WiFi Smart Mesh functionality of D-LINK DIR-3040 1.13B03. A specia...
CVE-2021-32999HIGH7.5Improper handling of exceptional conditions in SuiteLink server while processing command 0x01
CVE-2021-32987HIGH7.5Null pointer dereference in SuiteLink server while processing command 0x0b
CVE-2021-32979HIGH7.5Null pointer dereference in SuiteLink server while processing commands 0x04/0x0a
CVE-2021-32971HIGH7.5Null pointer dereference in SuiteLink server while processing command 0x07
CVE-2021-32963HIGH7.5Null pointer dereference in SuiteLink server while processing commands 0x03/0x10
CVE-2021-32959CRITICAL9.8Heap-based buffer overflow in SuiteLink server while processing commands 0x05/0x06
CVE-2021-22953MEDIUM5.4A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to clone topics which can lead to UI inconvenience, an...
CVE-2021-22952HIGH8.8A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained acc...
CVE-2021-22950MEDIUM6.5Concrete CMS prior to 8.5.6 had a CSFR vulnerability allowing attachments to comments in the conversation section to be ...
CVE-2021-22949MEDIUM5.4A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience,...
CVE-2021-22948HIGH7.1Vulnerability in the generation of session IDs in revive-adserver < 5.3.0, based on the cryptographically insecure uniqi...
CVE-2021-22945CRITICAL9.1When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer...
CVE-2021-22941CRITICAL9.8Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacke...
CVE-2021-22020MEDIUM5.5The vCenter Server contains a denial-of-service vulnerability in the Analytics service. Successful exploitation of this ...
CVE-2021-22019HIGH7.5The vCenter Server contains a denial-of-service vulnerability in VAPI (vCenter API) service. A malicious actor with netw...
CVE-2021-22018MEDIUM6.5The vCenter Server contains an arbitrary file deletion vulnerability in a VMware vSphere Life-cycle Manager plug-in. A m...
CVE-2021-22017MEDIUM5.3Rhttproxy as used in vCenter Server contains a vulnerability due to improper implementation of URI normalization. A mali...
CVE-2021-22016MEDIUM6.1The vCenter Server contains a reflected cross-site scripting vulnerability due to a lack of input sanitization. An attac...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now