2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40797MEDIUM6.5An issue was discovered in the routes middleware in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before...
CVE-2021-40537LOW2.7Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap ...
CVE-2021-38388HIGH8.8Central Dogma allows privilege escalation with mirroring to the internal dogma repository that has a file managing the a...
CVE-2021-36216HIGH7.8LINE for Windows 6.2.1.2289 and before allows arbitrary code execution via malicious DLL injection.
CVE-2021-36215MEDIUM5.3LINE client for iOS 10.21.3 and before allows address bar spoofing due to inappropriate address handling.
CVE-2021-32805MEDIUM6.1Flask-AppBuilder is an application development framework, built on top of Flask. In affected versions if using Flask-App...
CVE-2021-31274MEDIUM5.4In LibreNMS < 21.3.0, a stored XSS vulnerability was identified in the API Access page due to insufficient sanitization ...
CVE-2021-40346HIGH7.5An integer overflow exists in HAProxy 2.0 through 2.5 in htx_add_header that can be exploited to perform an HTTP request...
CVE-2021-3055MEDIUM6.5An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interf...
CVE-2021-3054MEDIUM6.6A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enab...
CVE-2021-3053HIGH7.5An improper handling of exceptional conditions vulnerability exists in the Palo Alto Networks PAN-OS dataplane that enab...
CVE-2021-3052MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in the Palo Alto Network PAN-OS web interface enables an authentica...
CVE-2021-3051HIGH8.1An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR SAML authentication that enable...
CVE-2021-3049MEDIUM4.3An improper authorization vulnerability in the Palo Alto Networks Cortex XSOAR server enables an authenticated network-b...
CVE-2021-33982HIGH7.5An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which...
CVE-2021-33981MEDIUM4.3An insecure, direct object vulnerability in hunting/fishing license retrieval function of the "Fish | Hunt FL" iOS app v...
CVE-2021-28732Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-28372. Reason: This candidate is a duplicate of ...
CVE-2021-28571HIGH8.8Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained w...
CVE-2021-28569MEDIUM4.3Adobe Media Encoder version 15.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a special...
CVE-2021-28568MEDIUM6.5Adobe Genuine Services version 7.1 (and earlier) is affected by an Insecure file permission vulnerability during install...
CVE-2021-28567MEDIUM6.5Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Improper Au...
CVE-2021-28566LOW2.7Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are vulnerable to an Information...
CVE-2021-21105HIGH8.8Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially c...
CVE-2021-21104HIGH8.8Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially c...
CVE-2021-21103HIGH8.8Adobe Illustrator version 25.2 (and earlier) is affected by a memory corruption vulnerability when parsing a specially c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now