2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22524MEDIUM4.9Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0.1 and 4.5.4
CVE-2021-40870CRITICAL9.8An issue was discovered in Aviatrix Controller 6.x before 6.5-1804.1922. Unrestricted upload of a file with a dangerous ...
CVE-2021-40867HIGH7.1Certain NETGEAR smart switches are affected by an authentication hijacking race-condition vulnerability by an unauthenti...
CVE-2021-40866HIGH8.8Certain NETGEAR smart switches are affected by a remote admin password change by an unauthenticated attacker via the (di...
CVE-2021-23435MEDIUM6.1This affects the package clearance before 2.5.0. The vulnerability can be possible when users are able to set the value ...
CVE-2021-23440CRITICAL9.8This affects the package set-value before <2.0.1, >=3.0.0 <4.0.1. A type confusion vulnerability can lead to a bypass of...
CVE-2021-40146CRITICAL9.8A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect A...
CVE-2021-38555CRITICAL9.1An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to a...
CVE-2021-39207HIGH8.8parlai is a framework for training and evaluating AI models on a variety of openly available dialogue datasets. In affec...
CVE-2021-24040CRITICAL9.8Due to use of unsafe YAML deserialization logic, an attacker with the ability to modify local YAML configuration files c...
CVE-2021-40864CRITICAL9.8The Translate plugin 6.1.x through 6.3.x before 6.3.0.72 for ONLYOFFICE Document Server lacks escape calls for the msg.d...
CVE-2021-40347MEDIUM5.4An issue was discovered in views/list.py in GNU Mailman Postorius before 1.3.5. An attacker (logged into any account) ca...
CVE-2021-3145MEDIUM6.7In Ionic Identity Vault before 5, a local root attacker on an Android device can bypass biometric authentication.
CVE-2021-3646MEDIUM6.1btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-37422CRITICAL9.8Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to SQL Injection while linking the databases.
CVE-2021-37423CRITICAL9.8Zoho ManageEngine ADSelfService Plus 6111 and prior is vulnerable to linked applications takeover.
CVE-2021-37418Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-31874. Reason: This candidate is a reservation d...
CVE-2021-37414HIGH7.5Zoho ManageEngine DesktopCentral before 10.0.709 allows anyone to get a valid user's APIKEY without authentication.
CVE-2021-40373CRITICAL9.8playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_con...
CVE-2021-38360CRITICAL9.8The wp-publications WordPress plugin is vulnerable to restrictive local file inclusion via the Q_FILE parameter found in...
CVE-2021-38359MEDIUM6.1The WordPress InviteBox Plugin for viral Refer-a-Friend Promotions WordPress plugin is vulnerable to Reflected Cross-Sit...
CVE-2021-38358MEDIUM6.1The MoolaMojo WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the classes parameter found in the ~/...
CVE-2021-38357MEDIUM6.1The SMS OVH WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the position parameter found in the ~/s...
CVE-2021-38355MEDIUM6.1The Bug Library WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the successimportcount parameter fo...
CVE-2021-38354MEDIUM6.1The GNU-Mailman Integration WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the gm_error parameter ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now