2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37703MEDIUM4.3Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a use...
CVE-2021-37693HIGH7.5Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when ...
CVE-2021-37586MEDIUM4.9The PowerPlay Web component of Mitel Interaction Recording Multitenancy systems before 6.7 could allow a user (with Admi...
CVE-2021-37028MEDIUM6.7There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is ...
CVE-2021-36380CRITICAL9.8Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dns...
CVE-2021-34398HIGH7.8NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared l...
CVE-2021-32072MEDIUM6.5The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code informatio...
CVE-2021-32071CRITICAL9.8The MiCollab Client service in Mitel MiCollab before 9.3 could allow an unauthenticated user to gain system access due t...
CVE-2021-32070MEDIUM5.4The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking att...
CVE-2021-32069MEDIUM4.8The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to impr...
CVE-2021-32068LOW3.7The AWV and MiCollab Client Service components in Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-...
CVE-2021-32067MEDIUM6.5The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system info...
CVE-2021-29880MEDIUM6.5IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information discl...
CVE-2021-27402MEDIUM6.5The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify...
CVE-2021-27401MEDIUM6.1The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) us...
CVE-2021-1104CRITICAL9.8The RISC-V Instruction Set Manual contains a documented ambiguity for the Machine Trap Vector Base Address (MTVEC) regis...
CVE-2021-38621CRITICAL9.1The remove API in v1/controller/cloudStorage/alibabaCloud/remove/index.ts in netless Agora Flat Server before 2021-07-30...
CVE-2021-38619MEDIUM6.1openBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduc...
CVE-2021-3635MEDIUM4.4A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_AD...
CVE-2021-3573MEDIUM6.4A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls io...
CVE-2021-38583MEDIUM6.1openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (...
CVE-2021-27741CRITICAL9.1" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
CVE-2021-31399MEDIUM5.9On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack.
CVE-2021-37353CRITICAL9.8Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in table_population.php.
CVE-2021-37352MEDIUM6.1An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vuln...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now