2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37541MEDIUM6.1In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.
CVE-2021-37540MEDIUM6.5In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.
CVE-2021-36708HIGH7.5In ProLink PRC2402M V1.0.18 and older, the set_sys_init function in the login.cgi binary allows an attacker to reset the...
CVE-2021-36707CRITICAL9.8In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter...
CVE-2021-36706CRITICAL9.8In ProLink PRC2402M V1.0.18 and older, the set_sys_cmd function in the adm.cgi binary, accessible with a page parameter ...
CVE-2021-36705CRITICAL9.8In ProLink PRC2402M V1.0.18 and older, the set_TR069 function in the adm.cgi binary, accessible with a page parameter va...
CVE-2021-36351CRITICAL9.8SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth...
CVE-2021-36209CRITICAL9.8In JetBrains Hub before 2021.1.13389, account takeover was possible during password reset.
CVE-2021-37381HIGH8.8Southsoft GMIS 5.0 is vulnerable to CSRF attacks. Attackers can access other users' private information such as photos t...
CVE-2021-22295MEDIUM5.5A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to ca...
CVE-2021-38152MEDIUM5.4index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.
CVE-2021-38151MEDIUM5.4index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.
CVE-2021-38149MEDIUM5.4index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.
CVE-2021-37388CRITICAL9.8A buffer overflow in D-Link DIR-615 C2 3.03WW. The ping_ipaddr parameter in ping_response.cgi POST request allows an att...
CVE-2021-32597MEDIUM5.4Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions...
CVE-2021-32587MEDIUM4.3An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 a...
CVE-2021-3655LOW3.3A vulnerability was found in the Linux kernel in versions prior to v5.14-rc1. Missing size validations on inbound SCTP p...
CVE-2021-3642MEDIUM5.3A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final ...
CVE-2021-3591Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2021-3580HIGH7.5A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could us...
CVE-2021-3566MEDIUM5.5Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitima...
CVE-2021-37632HIGH8.1SuperMartijn642's Config Lib is a library used by a number of mods for the game Minecraft. The versions of SuperMartijn6...
CVE-2021-37156HIGH7.5Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's ...
CVE-2021-35327CRITICAL9.8A vulnerability in TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers to start the Telnet service, th...
CVE-2021-35326HIGH7.5A vulnerability in TOTOLINK A720R router with firmware v4.1.5cu.470_B20200911 allows attackers to download the configura...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now