2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37794MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user auth...
CVE-2021-36234MEDIUM5.5Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspeci...
CVE-2021-36233MEDIUM6.5The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacke...
CVE-2021-36232HIGH8.8Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate p...
CVE-2021-36231HIGH8.8Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attacke...
CVE-2021-27668MEDIUM5.3HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authenti...
CVE-2021-3634MEDIUM6.5A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during th...
CVE-2021-39164LOW3.1Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorise...
CVE-2021-39135HIGH7.8`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the n...
CVE-2021-39134HIGH7.8`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the...
CVE-2021-37713HIGH8.6The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite ...
CVE-2021-37712HIGH8.6The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite ...
CVE-2021-37701HIGH8.6The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite a...
CVE-2021-35212HIGH8.8An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A bli...
CVE-2021-22944HIGH8A vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role an...
CVE-2021-22943CRITICAL9.6A vulnerability found in UniFi Protect application V1.18.1 and earlier permits a malicious actor who has already gained ...
CVE-2021-22929MEDIUM6.1An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that i...
CVE-2021-22684HIGH7.5Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memo...
CVE-2021-21811CRITICAL9.8A memory corruption vulnerability exists in the XML-parsing CreateLabelOrAttrib functionality of AT&T Labs’ Xmill 0.7. A...
CVE-2021-39163LOW3.1Matrix is an ecosystem for open federated Instant Messaging and Voice over IP. In versions 1.41.0 and prior, unauthorise...
CVE-2021-35240MEDIUM4.8A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they...
CVE-2021-35239MEDIUM5.4A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
CVE-2021-35223HIGH8.8The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command ...
CVE-2021-35213HIGH8.8An Improper Access Control Privilege Escalation Vulnerability was discovered in the User Setting of Orion Platform versi...
CVE-2021-29907HIGH8.8IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary co...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now