2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25955CRITICAL9In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows l...
CVE-2021-38699MEDIUM5.4TastyIgniter 3.0.7 allows XSS via /account, /reservation, /admin/dashboard, and /admin/system_logs.
CVE-2021-37326MEDIUM5.3NetSarang Xshell 7 before Build 0077 includes unintended code strings in paste operations.
CVE-2021-21815HIGH7.8A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs'...
CVE-2021-21814HIGH7.8Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the comman...
CVE-2021-21813HIGH7.8Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the comman...
CVE-2021-21812HIGH7.8A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’...
CVE-2021-37705CRITICAL10OneFuzz is an open source self-hosted Fuzzing-As-A-Service platform. Starting with OneFuzz 2.12.0 or greater, an incompl...
CVE-2021-21830CRITICAL9.8A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load functionality of AT&T Labs’ X...
CVE-2021-21829CRITICAL9.8A heap-based buffer overflow vulnerability exists in the XML Decompression EnumerationUncompressor::UncompressItem funct...
CVE-2021-38623HIGH7.5The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service ...
CVE-2021-38302CRITICAL9.8The Newsletter extension through 4.0.0 for TYPO3 allows SQL Injection.
CVE-2021-36793HIGH7.5The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitiv...
CVE-2021-36792HIGH7.2The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various ap...
CVE-2021-36791MEDIUM5.3The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registrat...
CVE-2021-36790MEDIUM6.1The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
CVE-2021-36789CRITICAL9.8The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
CVE-2021-36788MEDIUM5.4The yoast_seo (aka Yoast SEO) extension before 7.2.3 for TYPO3 allows XSS.
CVE-2021-36787MEDIUM5.4The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.
CVE-2021-36786HIGH7.5The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credent...
CVE-2021-36785MEDIUM5.4The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.
CVE-2021-34823CRITICAL9.1The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in...
CVE-2021-3352CRITICAL9.1The Software Development Kit in Mitel MiContact Center Business from 8.0.0.0 through 8.1.4.1 and 9.0.0.0 through 9.3.1.0...
CVE-2021-38554MEDIUM5.3HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a singl...
CVE-2021-38553MEDIUM4.4HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Int...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now