2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-36981HIGH8.8In the server in SerNet verinice before 1.22.2, insecure Java deserialization allows remote authenticated attackers to e...
CVE-2021-36356CRITICAL9.8KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa...
CVE-2021-27558MEDIUM6.1A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via...
CVE-2021-27557MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to upda...
CVE-2021-27556HIGH7.2The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by ...
CVE-2021-39178MEDIUM6.1Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability...
CVE-2021-39177CRITICAL9.8Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Versions of Geyser prior to 1.4.2-SNA...
CVE-2021-39175MEDIUM6.1HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject a...
CVE-2021-36692MEDIUM6.5libjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding...
CVE-2021-32832MEDIUM6.5Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before ...
CVE-2021-32831HIGH7.2Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP'...
CVE-2021-39133MEDIUM6.8Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.1...
CVE-2021-39132HIGH8.8Rundeck is an open source automation service with a web console, command line tools and a WebAPI. Prior to version 3.3.1...
CVE-2021-36691HIGH7.5libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a m...
CVE-2021-35062HIGH8.1A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attac...
CVE-2021-34434MEDIUM5.3In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make...
CVE-2021-38343MEDIUM6.1The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to an Open Redirect via the `page` POST parameter in the `npB...
CVE-2021-38342HIGH8.1The Nested Pages WordPress plugin <= 3.1.15 was vulnerable to Cross-Site Request Forgery via the `npBulkAction`s and `np...
CVE-2021-37421CRITICAL9.8Zoho ManageEngine ADSelfService Plus 6103 and prior is vulnerable to admin portal access-restriction bypass.
CVE-2021-37417CRITICAL9.8Zoho ManageEngine ADSelfService Plus version 6103 and prior allows CAPTCHA bypass due to improper parameter validation.
CVE-2021-37416MEDIUM6.1Zoho ManageEngine ADSelfService Plus version 6103 and prior is vulnerable to reflected XSS on the loadframe page.
CVE-2021-36370HIGH7.5An issue was discovered in Midnight Commander through 4.8.26. When establishing an SFTP connection, the fingerprint of t...
CVE-2021-35061MEDIUM6.1Multiple cross-site scripting (XSS) vulnerabilities in DRK Odenwaldkreis Testerfassung March-2021 allow remote attackers...
CVE-2021-34668MEDIUM5.4The WordPress Real Media Library WordPress plugin is vulnerable to Stored Cross-Site Scripting via the name parameter in...
CVE-2021-34646CRITICAL9.8Versions up to, and including, 5.4.3, of the Booster for WooCommerce WordPress plugin are vulnerable to authentication b...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now