2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34836HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0....
CVE-2021-34835HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0....
CVE-2021-34834HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0....
CVE-2021-34833HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0....
CVE-2021-34832HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0....
CVE-2021-34831HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.4.37...
CVE-2021-32596HIGH7.5A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 throu...
CVE-2021-26097HIGH8.8An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, ...
CVE-2021-36168MEDIUM6.5A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0....
CVE-2021-24018HIGH8.8A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker loc...
CVE-2021-24010MEDIUM6.5Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1...
CVE-2021-3678MEDIUM5.9showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2021-36765HIGH7.5In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the download...
CVE-2021-36764HIGH7.5In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a ...
CVE-2021-35463MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers t...
CVE-2021-33338HIGH7.5The Layout module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 before fix pack...
CVE-2021-33337MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 thro...
CVE-2021-32594HIGH8.1An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, ...
CVE-2021-32590HIGH8.8Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through...
CVE-2021-29765HIGH7.5IBM PowerVM Hypervisor FW940 and FW950 could allow an attacker to obtain sensitive information if they gain service acce...
CVE-2021-26098HIGH7.5An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possess...
CVE-2021-3680MEDIUM4.9showdoc is vulnerable to Missing Cryptographic Step
CVE-2021-33339MEDIUM4.8Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7...
CVE-2021-33336MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3,...
CVE-2021-36483HIGH8.8DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now