2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39113HIGH7.5Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached c...
CVE-2021-39111MEDIUM6.1The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from ve...
CVE-2021-26084CRITICAL9.8In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un...
CVE-2021-39272MEDIUM5.9Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation ...
CVE-2021-39271HIGH8.8OrbiTeam BSCW Classic before 7.4.3 allows authenticated remote code execution (RCE) during archive extraction via attack...
CVE-2021-38385HIGH7.5Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-s...
CVE-2021-36359HIGH8.8OrbiTeam BSCW Classic before 7.4.3 allows exportpdf authenticated remote code execution (RCE) via XML tag injection beca...
CVE-2021-37749CRITICAL9.8MapService.svc in Hexagon GeoMedia WebMap 2020 before Update 2 (aka 16.6.2.66) allows blind SQL Injection via the Id (wi...
CVE-2021-40178MEDIUM6.1Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
CVE-2021-40177CRITICAL9.8Zoho ManageEngine Log360 before Build 5225 allows remote code execution via BCP file overwrite.
CVE-2021-40176MEDIUM6.1Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
CVE-2021-40175CRITICAL9.8Zoho ManageEngine Log360 before Build 5219 allows unrestricted file upload with resultant remote code execution.
CVE-2021-40174HIGH8.8Zoho ManageEngine Log360 before Build 5224 allows a CSRF attack for disabling the logon security settings.
CVE-2021-40173HIGH8.8Zoho ManageEngine Cloud Security Plus before Build 4117 allows a CSRF attack on the server proxy settings.
CVE-2021-40172HIGH8.8Zoho ManageEngine Log360 before Build 5219 allows a CSRF attack on proxy settings.
CVE-2021-38154HIGH7.5Certain Canon devices manufactured in 2012 through 2020 (such as imageRUNNER ADVANCE iR-ADV C5250), when Catwalk Server ...
CVE-2021-39174HIGH8.8Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges...
CVE-2021-39173HIGH8.8Cachet is an open source status page system. Prior to version 2.5.1 authenticated users, regardless of their privileges ...
CVE-2021-39172HIGH8.8Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges...
CVE-2021-39171HIGH7.5Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3...
CVE-2021-32759HIGH7.2OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in ve...
CVE-2021-3264HIGH7.2SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php.
CVE-2021-28700MEDIUM4.9xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged...
CVE-2021-28699MEDIUM5.5inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant ...
CVE-2021-28698MEDIUM5.5long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the g...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now