2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31799HIGH7In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code ...
CVE-2021-30483MEDIUM5.3isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository.
CVE-2021-30124CRITICAL9.8The unofficial vscode-phpmd (aka PHP Mess Detector) extension before 1.3.0 for Visual Studio Code allows remote attacker...
CVE-2021-28966HIGH7.5In Ruby through 3.0 on Windows, a remote attacker can submit a crafted path when a Web application handles a parameter w...
CVE-2021-28674MEDIUM5.4The node management page in SolarWinds Orion Platform before 2020.2.5 HF1 allows an attacker to create or delete a node ...
CVE-2021-28095MEDIUM4.8OX Documents before 7.10.5-rev5 has Incorrect Access Control for documents that contain XML structures because hash coll...
CVE-2021-28094MEDIUM6.5OX Documents before 7.10.5-rev7 has Incorrect Access Control for converted documents because hash collisions can occur, ...
CVE-2021-28093MEDIUM6.5OX Documents before 7.10.5-rev5 has Incorrect Access Control of converted images because hash collisions can occur, due ...
CVE-2021-25200CRITICAL9.8Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbit...
CVE-2021-20789MEDIUM6.1Open redirect vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5.1.0, G...
CVE-2021-20788MEDIUM4.3Server-side request forgery (SSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version...
CVE-2021-20787MEDIUM4.8Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5...
CVE-2021-20786MEDIUM4.3Cross-site request forgery (CSRF) vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version ...
CVE-2021-20785MEDIUM4.8Cross-site scripting vulnerability in GroupSession (GroupSession Free edition from ver2.2.0 to the version prior to ver5...
CVE-2021-20783HIGH8.8Cross-site request forgery (CSRF) vulnerability in Optical BB unit E-WMTA2.3 allows a remote attacker to hijack the auth...
CVE-2021-20114HIGH7.5When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the ...
CVE-2021-20113MEDIUM5.3An exposure of sensitive information vulnerability exists in TCExam <= 14.8.1. If a password reset request was made for ...
CVE-2021-20112MEDIUM5.4A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.ph...
CVE-2021-20111MEDIUM5.4A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php wit...
CVE-2021-29781CRITICAL9.8IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an u...
CVE-2021-29736HIGH8.8IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote user to gain elevated privileges on the sys...
CVE-2021-36742HIGH7.8A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free B...
CVE-2021-36741HIGH8.8An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free...
CVE-2021-25273MEDIUM4.8Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706.
CVE-2021-23418CRITICAL9.8The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse unt...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now