2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-37394HIGH8.8In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user reg...
CVE-2021-37393MEDIUM5.4In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can ...
CVE-2021-37392MEDIUM5.4In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. When the API ...
CVE-2021-36563MEDIUM5.4The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the W...
CVE-2021-32792MEDIUM6.1mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co...
CVE-2021-32791MEDIUM5.9mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co...
CVE-2021-32790MEDIUM4.9Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sit...
CVE-2021-31292HIGH7.5An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and...
CVE-2021-31291Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-29457. Reason: This candidate is a duplicate of ...
CVE-2021-25804HIGH7.5A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the a...
CVE-2021-25803HIGH7.1A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows att...
CVE-2021-25802HIGH7.1A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attacker...
CVE-2021-25801HIGH7.1A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to ca...
CVE-2021-32789HIGH7.5woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerabilit...
CVE-2021-32631MEDIUM6.5Common is a package of common modules that can be accessed by NIMBLE services. Common before commit number 3b96cb0293d34...
CVE-2021-33629HIGH7.5isula-build before 0.9.5-6 can cause a program crash, when building container images, some functions for processing exte...
CVE-2021-37534MEDIUM5.4app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
CVE-2021-26824HIGH7.1DM FingerTool v1.19 in the DM PD065 Secure USB is susceptible to improper authentication by a replay attack, allowing lo...
CVE-2021-3664MEDIUM5.3url-parse is vulnerable to URL Redirection to Untrusted Site
CVE-2021-35030MEDIUM4.3A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize p...
CVE-2021-29784MEDIUM4.3IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2021-29770MEDIUM6.5IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform ...
CVE-2021-29769MEDIUM4.3IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authoriz...
CVE-2021-29767MEDIUM5.3IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information ...
CVE-2021-29766MEDIUM5.3IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now