2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40684CRITICAL9.1Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jo...
CVE-2021-37860MEDIUM6.1Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to ...
CVE-2021-41011HIGH7.5LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities un...
CVE-2021-40875HIGH7.5Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac...
CVE-2021-37927CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior allows account takeover via SSO.
CVE-2021-37925CRITICAL9.8Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
CVE-2021-31847HIGH7.8Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a lo...
CVE-2021-31841HIGH7.3A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sid...
CVE-2021-31836HIGH7.1Improper privilege management vulnerability in maconfig for McAfee Agent for Windows prior to 5.7.4 allows a local user ...
CVE-2021-39404MEDIUM4.8MaianAffiliate v1.0 allows an authenticated administrative user to save an XSS to the database.
CVE-2021-36260CRITICAL9.8A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation,...
CVE-2021-3583HIGH7.1A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through...
CVE-2021-39339MEDIUM5.3The Telefication WordPress plugin is vulnerable to Open Proxy and Server-Side Request Forgery via the ~/bypass.php file ...
CVE-2021-38153MEDIUM5.9Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks...
CVE-2021-38112HIGH8.8In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler...
CVE-2021-31819CRITICAL9.8In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on sy...
CVE-2021-41382HIGH7.5Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
CVE-2021-41087MEDIUM6.5in-toto-golang is a go implementation of the in-toto framework to protect software supply chain integrity. In affected v...
CVE-2021-41086MEDIUM5.4jsuites is an open source collection of common required javascript web components. In affected versions users are subjec...
CVE-2021-41084MEDIUM4.7http4s is an open source scala interface for HTTP. In affected versions http4s is vulnerable to response-splitting or re...
CVE-2021-40847HIGH8.1The update process of the Circle Parental Control Service on various NETGEAR routers allows remote attackers to achieve ...
CVE-2021-40868MEDIUM6.1In Cloudron 6.2, the returnTo parameter on the login page is vulnerable to Reflected XSS.
CVE-2021-39230MEDIUM6.5Butter is a system usability utility. Due to a kernel error the JPNS kernel is being discontinued. Affected users are re...
CVE-2021-23444CRITICAL9.8This affects the package jointjs before 3.4.2. A type confusion vulnerability can lead to a bypass of CVE-2020-28480 whe...
CVE-2021-23443MEDIUM6.1This affects the package edge.js before 5.3.2. A type confusion vulnerability can be used to bypass input sanitization w...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now