2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27953HIGH7.5A NULL pointer dereference vulnerability exists on the ecobee3 lite 4.5.81.200 device in the HomeKit Wireless Access Con...
CVE-2021-27952CRITICAL9.8Hardcoded default root credentials exist on the ecobee3 lite 4.5.81.200 device. This allows a threat actor to gain acces...
CVE-2021-36379Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-36159CRITICAL9.1libfetch before 2021-07-26, as used in apk-tools, xbps, and other products, mishandles numeric strings for the FTP and H...
CVE-2021-22400MEDIUM5.5Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An a...
CVE-2021-37833MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid applic...
CVE-2021-37832CRITICAL9.8A SQL injection vulnerability exists in version 3.0.2 of Hotel Druid when SQLite is being used as the application databa...
CVE-2021-35265MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attacke...
CVE-2021-37916MEDIUM6.1Joplin before 2.0.9 allows XSS via button and form in the note body.
CVE-2021-37914MEDIUM6.5In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input par...
CVE-2021-26085MEDIUM5.3Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza...
CVE-2021-21565MEDIUM5.3Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error ...
CVE-2021-21563MEDIUM6.5Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its ...
CVE-2021-21562MEDIUM4.4Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PR...
CVE-2021-21553HIGH8.8Dell PowerScale OneFS versions 8.1.0-9.1.0 contain an Incorrect User Management vulnerability.under some specific condit...
CVE-2021-32812MEDIUM6.1Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API serv...
CVE-2021-32811HIGH7.2Zope is an open-source web application server. Zope versions prior to versions 4.6.3 and 5.3 have a remote code executio...
CVE-2021-32787MEDIUM4.3Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leak...
CVE-2021-34637HIGH8.8The Post Index WordPress plugin is vulnerable to Cross-Site Request Forgery via the OptionsPage function found in the ~/...
CVE-2021-34635MEDIUM6.1The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/...
CVE-2021-34632HIGH8.8The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ...
CVE-2021-34628HIGH8.8The Admin Custom Login WordPress plugin is vulnerable to Cross-Site Request Forgery due to the loginbgSave action found ...
CVE-2021-32019MEDIUM6.1There is missing input validation of host names displayed in OpenWrt before 19.07.8. The Connection Status page of the l...
CVE-2021-29979MEDIUM6.1Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in ...
CVE-2021-27943HIGH7.5The pairing procedure used by the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs and mobile application is vu...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now