2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-38927MEDIUM6.1IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaS...
CVE-2021-22962CRITICAL9.1An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource...
CVE-2021-42797HIGH7.5Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthentic...
CVE-2021-42796CRITICAL9.8An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that a...
CVE-2021-42794MEDIUM5.3An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a ...
CVE-2021-3187HIGH8.8An issue was discovered in BeyondTrust Privilege Management for Mac before 5.7. An authenticated, unprivileged user can ...
CVE-2021-46899HIGH7.8SyncTrayzor 1.1.29 enables CEF (Chromium Embedded Framework) remote debugging, allowing a local attacker to control the ...
CVE-2021-27795HIGH8.1Brocade Fabric OS (FOS) hardware platforms running any version of Brocade Fabric OS software, which supports the licen...
CVE-2021-35975MEDIUM5.3Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius...
CVE-2021-36806MEDIUM6.1 A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sop...
CVE-2021-39008MEDIUM4.9 IBM QRadar WinCollect Agent 10.0 through 10.1.7 could allow a privileged user to obtain sensitive information due to mi...
CVE-2021-37942HIGH7.8A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a maliciou...
CVE-2021-37937HIGH8.8An issue was found with how API keys are created with the Fleet-Server service account. When an API key is created with ...
CVE-2021-22143MEDIUM4.3The Elastic APM .NET Agent can leak sensitive HTTP header information when logging the details during an application err...
CVE-2021-22151MEDIUM4.3It was discovered that Kibana was not validating a user supplied path, which would load .pbf files. Because of this, a m...
CVE-2021-22150HIGH7.2It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older versi...
CVE-2021-22142HIGH8.8Kibana contains an embedded version of the Chromium browser that the Reporting feature uses to generate the downloadable...
CVE-2021-38405HIGH7.8The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specia...
CVE-2021-27504HIGH7.8Texas Instruments devices running FREERTOS, malloc returns a valid pointer to a small buffer on extremely large values,...
CVE-2021-27502HIGH7.8Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a small buff...
CVE-2021-27429HIGH7.8 Texas Instruments TI-RTOS returns a valid pointer to a small buffer on extremely large values. This can trigger an inte...
CVE-2021-22636HIGH7.8 Texas Instruments TI-RTOS, when configured to use HeapMem heap(default), malloc returns a valid pointer to a smal...
CVE-2021-35437CRITICAL9.8SQL injection vulnerability in LMXCMS v.1.4 allows attacker to execute arbitrary code via the TagsAction.class.
CVE-2021-46774HIGH7.5Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an inva...
CVE-2021-46766MEDIUM5.5Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now