2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-35325HIGH7.5A stack overflow in the checkLoginUser function of TOTOLINK A720R A720R_Firmware v4.1.5cu.470_B20200911 allows attackers...
CVE-2021-35324CRITICAL9.8A vulnerability in the Form_Login function of TOTOLINK A720R A720R_Firmware V4.1.5cu.470_B20200911 allows attackers to b...
CVE-2021-34639HIGH8.8Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files w...
CVE-2021-34638MEDIUM6.5Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to o...
CVE-2021-34634HIGH8.8The Nifty Newsletters WordPress plugin is vulnerable to Cross-Site Request Forgery via the sola_nl_wp_head function foun...
CVE-2021-34633HIGH8.8The Youtube Feeder WordPress plugin is vulnerable to Cross-Site Request Forgery via the printAdminPage function found in...
CVE-2021-32003MEDIUM5.5Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture ...
CVE-2021-32002LOW3.3Improper Access Control vulnerability in web service of Secomea SiteManager allows local attacker without credentials to...
CVE-2021-28216HIGH7.8BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3S...
CVE-2021-26605CRITICAL9.8An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. T...
CVE-2021-26586HIGH7.5A potential security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edg...
CVE-2021-22928HIGH7.8A vulnerability has been identified in Citrix Virtual Apps and Desktops that could, if exploited, allow a user of a Wind...
CVE-2021-22927HIGH8.1A session fixation vulnerability exists in Citrix ADC and Citrix Gateway 13.0-82.45 when configured SAML service provide...
CVE-2021-22926HIGH7.5libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CU...
CVE-2021-22925MEDIUM5.3curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used ...
CVE-2021-22924LOW3.7libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches ...
CVE-2021-22923MEDIUM5.3When curl is instructed to get content using the metalink feature, and a user name and password are used to download the...
CVE-2021-22922MEDIUM6.5When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided ...
CVE-2021-22920MEDIUM6.5A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known a...
CVE-2021-22919HIGH7.5A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known a...
CVE-2021-22517HIGH8.8A potential unauthorized privilege escalation vulnerability has been identified in Micro Focus Data Protector. The vulne...
CVE-2021-22234MEDIUM6.4An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions sta...
CVE-2021-21893HIGH8.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 11.0.0.49893. A s...
CVE-2021-21870HIGH8.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.4.37651. A s...
CVE-2021-21831HIGH8.8A use-after-free vulnerability exists in the JavaScript engine of Foxit Software’s PDF Reader, version 10.1.3.37598. A s...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now