2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34066CRITICAL9.8An issue was discovered in EdgeGallery/developer before v1.0. There is a "Deserialization of yaml file" vulnerability th...
CVE-2021-33055CRITICAL9.8Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
CVE-2021-29630HIGH8.1In FreeBSD 13.0-STABLE before n246938-0729ba2f49c9, 12.2-STABLE before r370383, 11.4-STABLE before r370381, 13.0-RELEASE...
CVE-2021-22021MEDIUM5.4VMware vRealize Log Insight (8.x prior to 8.4) contains a Cross Site Scripting (XSS) vulnerability due to improper user ...
CVE-2021-3628MEDIUM5.4OpenKM Community Edition in its 6.3.10 version is vulnerable to authenticated Cross-site scripting (XSS). A remote attac...
CVE-2021-38393CRITICAL9.8A Blind SQL injection vulnerability exists in the /DataHandler/HandlerAlarmGroup.ashx endpoint of Delta Electronics DIAE...
CVE-2021-38391CRITICAL9.8A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnerg...
CVE-2021-38390CRITICAL9.8A Blind SQL injection vulnerability exists in the /DataHandler/HandlerEnergyType.ashx endpoint of Delta Electronics DIAE...
CVE-2021-33019HIGH7.8A stack-based buffer overflow vulnerability in Delta Electronics DOPSoft Version 4.00.11 and prior may be exploited by p...
CVE-2021-33007HIGH7.8A heap-based buffer overflow in Delta Electronics TPEditor: v1.98.06 and prior may be exploited by processing a speciall...
CVE-2021-33003MEDIUM5.5Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to retrieve passwords in cleartext due to a w...
CVE-2021-32991MEDIUM4.3Delta Electronics DIAEnergie Version 1.7.5 and prior is vulnerable to cross-site request forgery, which may allow an att...
CVE-2021-32983CRITICAL9.8A Blind SQL injection vulnerability exists in the /DataHandler/Handler_CFG.ashx endpoint of Delta Electronics DIAEnergie...
CVE-2021-32967CRITICAL9.8Delta Electronics DIAEnergie Version 1.7.5 and prior may allow an attacker to add a new administrative user without bein...
CVE-2021-32955CRITICAL9.8Delta Electronics DIAEnergie Version 1.7.5 and prior allows unrestricted file uploads, which may allow an attacker to re...
CVE-2021-29631HIGH7.8In FreeBSD 13.0-STABLE before n246941-20f96f215562, 12.2-STABLE before r370400, 11.4-STABLE before r370399, 13.0-RELEASE...
CVE-2021-27663CRITICAL9.8A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access ...
CVE-2021-27020HIGH8.8Puppet Enterprise presented a security risk by not sanitizing user input when doing a CSV export.
CVE-2021-27019MEDIUM4.3PuppetDB logging included potentially sensitive system information.
CVE-2021-27018HIGH7.5The mechanism which performs certificate validation was discovered to have a flaw that resulted in certificates signed b...
CVE-2021-22027HIGH7.5The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauth...
CVE-2021-22026HIGH7.5The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauth...
CVE-2021-22025HIGH7.5The vRealize Operations Manager API (8.x prior to 8.5) contains a broken access control vulnerability leading to unauthe...
CVE-2021-22024HIGH7.5The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthentic...
CVE-2021-22023HIGH7.2The vRealize Operations Manager API (8.x prior to 8.5) has insecure object reference vulnerability. A malicious actor wi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now