2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29831HIGH8.1IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Inje...
CVE-2021-29795MEDIUM6IBM PowerVM Hypervisor FW860, FW930, FW940, and FW950 could allow a local user to create a specially crafted sequence of...
CVE-2021-41525MEDIUM5.5An issue related to modification of otherwise restricted files through a locally authenticated attacker exists in FlexNe...
CVE-2021-41531HIGH7.5NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length...
CVE-2021-37741HIGH8.8ManageEngine ADManager Plus before 7111 has Pre-authentication RCE vulnerabilities.
CVE-2021-37424CRITICAL9.8ManageEngine ADSelfService Plus before 6112 is vulnerable to domain user account takeover.
CVE-2021-37420MEDIUM6.5Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
CVE-2021-37419HIGH7.5Zoho ManageEngine ADSelfService Plus before 6112 is vulnerable to SSRF.
CVE-2021-28960CRITICAL9.8Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handlin...
CVE-2021-0869CRITICAL9.8In GetTimeStampAndPkt of DumpstateDevice.cpp, there is a possible out of bounds write due to an incorrect bounds check. ...
CVE-2021-31917CRITICAL9.8A flaw was found in Red Hat DataGrid 8.x (8.0.0, 8.0.1, 8.1.0 and 8.1.1) and Infinispan (10.0.0 through 12.0.0). An atta...
CVE-2021-26333MEDIUM5.5An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionar...
CVE-2021-20829MEDIUM6.1Cross-site scripting vulnerability due to the inadequate tag sanitization in GROWI versions v4.2.19 and earlier allows r...
CVE-2021-20037HIGH7.8SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads t...
CVE-2021-41083HIGH8.8Dada Mail is a web-based e-mail list management system. In affected versions a bad actor could give someone a carefully ...
CVE-2021-39229HIGH7.5Apprise is an open source library which allows you to send a notification to almost all of the most popular notification...
CVE-2021-41082HIGH7.5Discourse is a platform for community discussion. In affected versions any private message that includes a group had its...
CVE-2021-34650MEDIUM6.1The eID Easy WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the error parameter found in the ~/adm...
CVE-2021-39325MEDIUM6.1The OptinMonster WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to insufficient input validation i...
CVE-2021-32838HIGH7.5Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is...
CVE-2021-38899MEDIUM4.4IBM Cloud Pak for Data 2.5 could allow a local user with special privileges to obtain highly sensitive information. IBM ...
CVE-2021-32839HIGH7.5sqlparse is a non-validating SQL parser module for Python. In sqlparse versions 0.4.0 and 0.4.1 there is a regular Expre...
CVE-2021-29856MEDIUM6.5IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 could allow an authenticated usre to cause a denial of service through the WebGUI M...
CVE-2021-29821MEDIUM5.4IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vul...
CVE-2021-29820MEDIUM5.4IBM Jazz for Service Management and IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vul...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now