2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39497CRITICAL9.8eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveR...
CVE-2021-39496MEDIUM5.4Eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject malicious code into `filename` param to t...
CVE-2021-39194MEDIUM6.5kaml is an open source implementation of the YAML format with support for kotlinx.serialization. In affected versions at...
CVE-2021-38707MEDIUM5.4Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce a...
CVE-2021-38706HIGH8.8messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged att...
CVE-2021-38705HIGH8.8ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticate...
CVE-2021-38704MEDIUM6.1Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to in...
CVE-2021-37631MEDIUM6.5Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams inte...
CVE-2021-37630MEDIUM6.5Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud...
CVE-2021-35948MEDIUM5.4Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass th...
CVE-2021-35946CRITICAL9.8A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissio...
CVE-2021-32782MEDIUM5.4Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud...
CVE-2021-39199MEDIUM6.1remark-html is an open source nodejs library which compiles Markdown to HTML. In affected versions the documentation of ...
CVE-2021-39196MEDIUM6.5pcapture is an open source dumpcap web service interface . In affected versions this vulnerability allows an authenticat...
CVE-2021-39195MEDIUM6.5Misskey is an open source, decentralized microblogging platform. In affected versions a Server-Side Request Forgery vuln...
CVE-2021-35949MEDIUM5.3The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upl...
CVE-2021-35947MEDIUM5.3The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal pa...
CVE-2021-39197HIGH8.8better_errors is an open source replacement for the standard Rails error page with more information rich error pages. It...
CVE-2021-38142HIGH8.8Barco MirrorOp Windows Sender before 2.5.3.65 uses cleartext HTTP and thus allows rogue software upgrades. An attacker o...
CVE-2021-40539CRITICAL9.8Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta...
CVE-2021-38123MEDIUM6.1Open Redirect vulnerability in Micro Focus Network Automation, affecting Network Automation versions 10.4x, 10.5x, 2018....
CVE-2021-39263HIGH7.8A crafted NTFS image can trigger a heap-based buffer overflow, caused by an unsanitized attribute in ntfs_get_attribute_...
CVE-2021-39262HIGH7.8A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.
CVE-2021-39261HIGH7.8A crafted NTFS image can cause a heap-based buffer overflow in ntfs_compressed_pwrite in NTFS-3G < 2021.8.22.
CVE-2021-39260HIGH7.8A crafted NTFS image can cause an out-of-bounds access in ntfs_inode_sync_standard_information in NTFS-3G < 2021.8.22.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now