2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21546MEDIUM5.5Dell EMC NetWorker versions 18.x,19.x prior to 19.3.0.4 and 19.4.0.0 contain an Information Disclosure in Log Files vuln...
CVE-2021-21538CRITICAL10Dell EMC iDRAC9 versions 4.40.00.00 and later, but prior to 4.40.10.00, contain an improper authentication vulnerability...
CVE-2021-20505MEDIUM4.4The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange ...
CVE-2021-37578CRITICAL9.8Apache jUDDI uses several classes related to Java's Remote Method Invocation (RMI) which (as an extension to UDDI) provi...
CVE-2021-23417CRITICAL9.8All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
CVE-2021-23416MEDIUM6.1This affects all versions of package curly-bracket-parser. When used as a template library, it does not properly sanitiz...
CVE-2021-23415HIGH7.5This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it...
CVE-2021-32001MEDIUM6.5K3s in SUSE Rancher allows any user with direct access to the datastore, or a copy of a datastore backup, to extract the...
CVE-2021-32000HIGH7.1A UNIX Symbolic Link (Symlink) Following vulnerability in the clone-master-clean-up.sh script of clone-master-clean-up i...
CVE-2021-23414MEDIUM6.1This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execu...
CVE-2021-32796MEDIUM5.3xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. x...
CVE-2021-32788MEDIUM4.3Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post cre...
CVE-2021-32748MEDIUM4.3Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Plat...
CVE-2021-34432HIGH7.5In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with...
CVE-2021-20562MEDIUM5.4IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_3 and 6.1.0.0 through 6.1.0.2 vulnerable to cross-s...
CVE-2021-20399CRITICAL9.1IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) att...
CVE-2021-37576HIGH7.8arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to c...
CVE-2021-37555CRITICAL9.8TX9 Automatic Food Dispenser v3.2.57 devices allow access to a shell as root/superuser, a related issue to CVE-2019-1673...
CVE-2021-32795MEDIUM5.9ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. In ...
CVE-2021-32794HIGH7.5ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due...
CVE-2021-37478CRITICAL9.8In NavigateCMS version 2.9.4 and below, function `block` is vulnerable to sql injection on parameter `block-order`, whic...
CVE-2021-37477CRITICAL9.8In NavigateCMS version 2.9.4 and below, function in `structure.php` is vulnerable to sql injection on parameter `childre...
CVE-2021-37476CRITICAL9.8In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `id` throu...
CVE-2021-37475CRITICAL9.8In NavigateCMS version 2.9.4 and below, function in `templates.php` is vulnerable to sql injection on parameter `templat...
CVE-2021-37473CRITICAL9.8In NavigateCMS version 2.9.4 and below, function in `product.php` is vulnerable to sql injection on parameter `products-...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now