2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37366HIGH8.8CTparental before 4.45.03 is vulnerable to cross-site request forgery (CSRF) in the CTparental admin panel. By combining...
CVE-2021-37365MEDIUM6.1CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_hel...
CVE-2021-32768MEDIUM6.1TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing...
CVE-2021-38373MEDIUM5.3In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Ser...
CVE-2021-38372LOW3.7In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server ar...
CVE-2021-38371HIGH7.5The STARTTLS feature in Exim through 4.94.2 allows response injection (buffering) during MTA SMTP sending.
CVE-2021-38370MEDIUM5.9In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
CVE-2021-36601MEDIUM6.1GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settin...
CVE-2021-33707MEDIUM6.1SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing ...
CVE-2021-33706MEDIUM4.3Due to improper input validation in InfraBox, logs can be modified by an authenticated user.
CVE-2021-33703MEDIUM6.1Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode U...
CVE-2021-33702MEDIUM6.1Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not suf...
CVE-2021-33699MEDIUM6.5Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in ...
CVE-2021-32943CRITICAL9.8The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arb...
CVE-2021-22676MEDIUM6.1UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to se...
CVE-2021-38365LOW3.7Winner (aka ToneWinner) desktop speakers through 2021-08-09 allow remote attackers to recover speech signals from the po...
CVE-2021-37152MEDIUM5.4Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the abili...
CVE-2021-29739MEDIUM4.9IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is ret...
CVE-2021-22674MEDIUM6.5The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unautho...
CVE-2021-22386HIGH7A component of the Huawei smartphone has a Double Free vulnerability. Local attackers may exploit this vulnerability to ...
CVE-2021-22385HIGH7.8A component of the Huawei smartphone has a External Control of System or Configuration Setting vulnerability. Local atta...
CVE-2021-31655MEDIUM6.1Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter....
CVE-2021-3689HIGH7.5yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
CVE-2021-37180HIGH7.8A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library lacks prop...
CVE-2021-37179HIGH7.8A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library in affecte...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now