2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23428CRITICAL9.8This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file p...
CVE-2021-23427CRITICAL9.8This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to ...
CVE-2021-23426HIGH7.5This affects all versions of package Proto. It is possible to inject pollute the object property of an application using...
CVE-2021-39170MEDIUM5.4Pimcore is an open source data & experience management platform. Prior to version 10.1.2, an authenticated user could ad...
CVE-2021-39166MEDIUM5.4Pimcore is an open source data & experience management platform. Prior to version 10.1.2, text-values were not properly ...
CVE-2021-35508HIGH8.8NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges vi...
CVE-2021-40352MEDIUM6.5OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can re...
CVE-2021-39379CRITICAL9.8A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma...
CVE-2021-39378CRITICAL9.8A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma...
CVE-2021-39377CRITICAL9.8A SQL Injection vulnerability exists in openSIS 8.0 when MySQL (MariaDB) is being used as the application database. A ma...
CVE-2021-39373HIGH7.8Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk manageme...
CVE-2021-37151MEDIUM5.3CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is v...
CVE-2021-38703HIGH8.8Wireless devices running certain Arcadyan-derived firmware (such as KPN Experia WiFi 1.00.15) do not properly sanitise u...
CVE-2021-35238MEDIUM4.8User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.
CVE-2021-39109HIGH7.5The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary ...
CVE-2021-37415CRITICAL9.8Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs w...
CVE-2021-33582HIGH7.5Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input tha...
CVE-2021-40353CRITICAL9.8A SQL injection vulnerability exists in version 8.0 of openSIS when MySQL or MariaDB is used as the application database...
CVE-2021-36235HIGH7.8An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges c...
CVE-2021-22003HIGH7.5VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious ac...
CVE-2021-22002CRITICAL9.8VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be a...
CVE-2021-22029HIGH7.5VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/syst...
CVE-2021-40085MEDIUM6.5An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated at...
CVE-2021-39180HIGH8.8OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15....
CVE-2021-39176HIGH7.5detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now