2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40669CRITICAL9.8SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords parameter under the coreframe/app/promote/admin/i...
CVE-2021-29842MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to e...
CVE-2021-29825HIGH7.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive information when using ADMIN_...
CVE-2021-29763MEDIUM5.1IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could al...
CVE-2021-29752MEDIUM4.4IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privilege...
CVE-2021-41079HIGH7.5Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets...
CVE-2021-40438CRITICAL9A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. Th...
CVE-2021-39275CRITICAL9.8ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted d...
CVE-2021-39239HIGH7.5A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External...
CVE-2021-39214CRITICAL9.8mitmproxy is an interactive, SSL/TLS-capable intercepting proxy. In mitmproxy 7.0.2 and below, a malicious client or ser...
CVE-2021-39208MEDIUM4.3SharpCompress is a fully managed C# library to deal with many compression types and formats. Versions prior to 0.29.0 ar...
CVE-2021-36160HIGH7.5A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This ...
CVE-2021-34798HIGH7.5Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and ...
CVE-2021-27341CRITICAL9.8OpenSIS Community Edition version <= 7.6 is affected by a local file inclusion vulnerability in DownloadWindow.php via t...
CVE-2021-27340MEDIUM6.1OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" pa...
CVE-2021-34576MEDIUM4.3In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists. This may give...
CVE-2021-34573MEDIUM5.5In Enbra EWM in Version 1.7.29 together with several tested wireless M-Bus Sensors the events backflow and "no flow" are...
CVE-2021-34572MEDIUM6.5Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead tim...
CVE-2021-34571MEDIUM6.5Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an option to change the e...
CVE-2021-40067MEDIUM6.8The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by ...
CVE-2021-40066MEDIUM5.3The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both netwo...
CVE-2021-39128HIGH7.2Affected versions of Atlassian Jira Server or Data Center using the Jira Service Management addon allow remote attackers...
CVE-2021-40881CRITICAL9.8An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.
CVE-2021-40639HIGH7.5Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.proper...
CVE-2021-33045CRITICAL9.8The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now