2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21805CRITICAL9.8An OS Command Injection vulnerability exists in the ping.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10....
CVE-2021-21792MEDIUM5.5An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handl...
CVE-2021-21791MEDIUM5.5An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handl...
CVE-2021-21790MEDIUM5.5An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handl...
CVE-2021-21785MEDIUM5.5An information disclosure vulnerability exists in the IOCTL 0x9c40a148 handling of IOBit Advanced SystemCare Ultimate 14...
CVE-2021-20592HIGH7.5Missing synchronization vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.39...
CVE-2021-20116MEDIUM6.1A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir param...
CVE-2021-20115MEDIUM6.1A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir param...
CVE-2021-1630HIGH7.5XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub,...
CVE-2021-3682HIGH8.5A flaw was found in the USB redirector device emulation of QEMU in versions prior to 6.1.0-rc2. It occurs when dropping ...
CVE-2021-3679MEDIUM5.5A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the w...
CVE-2021-37859MEDIUM6.1Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
CVE-2021-37614HIGH8.8In certain Progress MOVEit Transfer versions before 2021.0.3 (aka 13.0.3), SQL injection in the MOVEit Transfer web appl...
CVE-2021-36584MEDIUM5.5An issue was discovered in GPAC 1.0.1. There is a heap-based buffer overflow in the function gp_rtp_builder_do_tx3g func...
CVE-2021-35307MEDIUM6.5An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the AP4_DescriptorFinder::Tes...
CVE-2021-35306MEDIUM6.5An issue was discovered in Bento4 through v1.6.0-636. A NULL pointer dereference exists in the function AP4_StszAtom::Wr...
CVE-2021-34631HIGH8.8The NewsPlugin WordPress plugin is vulnerable to Cross-Site Request Forgery via the handle_save_style function found in ...
CVE-2021-34371CRITICAL9.8Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, ...
CVE-2021-33597MEDIUM5.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F...
CVE-2021-33596MEDIUM4.1Showing the legitimate URL in the address bar while loading the content from other domain. This makes the user believe t...
CVE-2021-32581HIGH8.1Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent ...
CVE-2021-32580HIGH7.8Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking.
CVE-2021-32579HIGH7.8Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an...
CVE-2021-32578HIGH7.8Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handl...
CVE-2021-32577HIGH7.8Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now