2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-35312HIGH7.8A vulnerability was found in CIR 2000 / Gestionale Amica Prodigy v1.7. The Amica Prodigy's executable "RemoteBackup.Serv...
CVE-2021-36795HIGH7.8A permission issue in the Cohesity Linux agent may allow privilege escalation in version 6.5.1b to 6.5.1d-hotfix10, 6.6....
CVE-2021-20598MEDIUM5.3Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16...
CVE-2021-20597CRITICAL9.1Insufficiently Protected Credentials vulnerability in Mitsubishi Electric MELSEC iQ-R series Safety CPU modules R08/16/3...
CVE-2021-20594HIGH7.5Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Mitsubishi Electric MELSEC iQ-R series Safet...
CVE-2021-36455HIGH8.8SQL Injection vulnerability in Naviwebs Navigate CMS 2.9 via the quicksearch parameter in \lib\packages\comments\comment...
CVE-2021-36454MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\b...
CVE-2021-38137HIGH8.1Corero SecureWatch Managed Services 9.7.2.0020 does not correctly check swa-monitor and cns-monitor user’s privileges, a...
CVE-2021-38136MEDIUM6.5Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter...
CVE-2021-26999MEDIUM4.3NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The lo...
CVE-2021-26998MEDIUM4.3NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Cu...
CVE-2021-26606CRITICAL9.8A vulnerability in PKI Security Solution of Dream Security could allow arbitrary command execution. This vulnerability i...
CVE-2021-37554MEDIUM4.3In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
CVE-2021-37553HIGH7.5In JetBrains YouTrack before 2021.2.16363, an insecure PRNG was used.
CVE-2021-37552MEDIUM5.4In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
CVE-2021-37551MEDIUM5.3In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
CVE-2021-37550HIGH7.5In JetBrains YouTrack before 2021.2.16363, time-unsafe comparisons were used.
CVE-2021-37549CRITICAL9.1In JetBrains YouTrack before 2021.1.11111, sandboxing in workflows was insufficient.
CVE-2021-37548HIGH7.5In JetBrains TeamCity before 2021.1, passwords in cleartext sometimes could be stored in VCS.
CVE-2021-37547MEDIUM5.3In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.
CVE-2021-37546MEDIUM5.3In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
CVE-2021-37545HIGH7.5In JetBrains TeamCity before 2021.1.1, insufficient authentication checks for agent requests were made.
CVE-2021-37544CRITICAL9.8In JetBrains TeamCity before 2020.2.4, there was an insecure deserialization.
CVE-2021-37543HIGH8.8In JetBrains RubyMine before 2021.1.1, code execution without user confirmation was possible for untrusted projects.
CVE-2021-37542MEDIUM6.1In JetBrains TeamCity before 2020.2.3, XSS was possible.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now