2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34407Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-30480. Reason: This candidate is a reservation d...
CVE-2021-37711HIGH8.8Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Ver...
CVE-2021-37710MEDIUM5.4Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a Cross-Site Scripting vulnerability vi...
CVE-2021-37709MEDIUM6.5Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability involving an insecure d...
CVE-2021-36282LOW3.3Dell EMC PowerScale OneFS versions 8.2.x - 9.1.0.x contain a use of uninitialized resource vulnerability. This can poten...
CVE-2021-36281HIGH8.8Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privile...
CVE-2021-36280MEDIUM5.5Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulner...
CVE-2021-36279HIGH7.8Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulner...
CVE-2021-36278MEDIUM5.5Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in...
CVE-2021-21599MEDIUM6.7Dell EMC PowerScale OneFS versions 8.2.x - 9.2.1.x contain an OS command injection vulnerability. This may allow a user ...
CVE-2021-21595MEDIUM6.7Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS ...
CVE-2021-21594MEDIUM5.3Dell PowerScale OneFS versions 8.2.2 - 9.1.0.x contain a use of get request method with sensitive query strings vulnerab...
CVE-2021-21592MEDIUM6.5Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x improperly handle an exceptional condition. A remote low privileged use...
CVE-2021-21568MEDIUM4.3Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an insufficient logging vulnerability. An authenticated user wi...
CVE-2021-32827CRITICAL9.6MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An att...
CVE-2021-32826HIGH8.1Proxyee-Down is open source proxy software. An attacker being able to provide an extension script (eg: through a MiTM at...
CVE-2021-38608HIGH7.8Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to ...
CVE-2021-37708CRITICAL9.8Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in ma...
CVE-2021-21861HIGH8.8An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A...
CVE-2021-21860HIGH8.8An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A...
CVE-2021-21859HIGH8.8An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A...
CVE-2021-38315MEDIUM6.1The SP Project & Document Manager WordPress plugin is vulnerable to attribute-based Reflected Cross-Site Scripting via t...
CVE-2021-37707HIGH7.5Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulatio...
CVE-2021-34667MEDIUM6.1The Calendar_plugin WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of `$_SERVER['PHP_SE...
CVE-2021-34666MEDIUM6.1The Add Sidebar WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the add parameter in the ~/wp_sideb...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now