2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-41715HIGH8.8libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
CVE-2021-46367HIGH7.2RiteCMS version 3.1.0 and below suffers from a remote code execution vulnerability in the admin panel. An authenticated ...
CVE-2021-46436HIGH7.2An issue was discovered in ZZCMS 2021. There is a SQL injection vulnerability in ad_manage.php.
CVE-2021-36202HIGH8.8Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to in...
CVE-2021-43430HIGH8.8An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a mal...
CVE-2021-43429HIGH7.5A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a fail...
CVE-2021-46418HIGH7.5An unauthorized file creation vulnerability in Telesquare TLR-2855KS6 via PUT method can allow creation of CGI scripts.
CVE-2021-46417HIGH7.5Insecure handling of a download function leads to disclosure of internal files due to path traversal with root privilege...
CVE-2021-46416HIGH8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups acce...
CVE-2021-43138HIGH7.8In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/i...
CVE-2021-26116HIGH8.8An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of Fo...
CVE-2021-26113HIGH7.5A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker w...
CVE-2021-26104HIGH7.8Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6....
CVE-2021-22127HIGH8An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x befo...
CVE-2021-44169HIGH8.8A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6...
CVE-2021-24009HIGH8.8Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of Fo...
CVE-2021-45104HIGH7.4An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker who can capture HTCondor net...
CVE-2021-30497HIGH7.5Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal...
CVE-2021-45103HIGH8.1An issue was discovered in HTCondor 9.0.x before 9.0.10 and 9.1.x before 9.5.1. An attacker can access files stored in S...
CVE-2021-27117HIGH7.8An issue was discovered in file profile.go in function GetCPUProfile in beego through 2.0.2, allows attackers to launch ...
CVE-2021-27116HIGH7.8An issue was discovered in file profile.go in function MemProf in beego through 2.0.2, allows attackers to launch symlin...
CVE-2021-41245HIGH8.1Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, CSRF tokens generated by `...
CVE-2021-38834HIGH8.8easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through ...
CVE-2021-39114HIGH8.8Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data C...
CVE-2021-45893HIGH7.5An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is Improper Handling of Case Sensitivity, which makes...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now