2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22144MEDIUM6.5In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial o...
CVE-2021-20560MEDIUM5.4IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the click...
CVE-2021-20431MEDIUM6.5IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an ...
CVE-2021-20430MEDIUM5.3IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi...
CVE-2021-20337HIGH7.5IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that cou...
CVE-2021-33900HIGH7.5While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL auth...
CVE-2021-36092MEDIUM6.1It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This is...
CVE-2021-36091MEDIUM4.3Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS))...
CVE-2021-21443MEDIUM4.3Agents are able to list customer user emails without required permissions in the bulk action screen. This issue affects:...
CVE-2021-21442MEDIUM5.4In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed...
CVE-2021-21440MEDIUM6.5Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: O...
CVE-2021-37449MEDIUM5.4Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
CVE-2021-37448MEDIUM5.4Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
CVE-2021-37447HIGH8.1In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file ...
CVE-2021-37446MEDIUM4.3In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file re...
CVE-2021-37445MEDIUM6.5In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via logprop?file=/.. for file reading...
CVE-2021-37444HIGH8.8NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive....
CVE-2021-37443HIGH8.1NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
CVE-2021-37442MEDIUM6.5NCH IVM Attendant v5.12 and earlier allows path traversal via viewfile?file=/.. to read files.
CVE-2021-37441HIGH8.8NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.
CVE-2021-37440MEDIUM6.5NCH Axon PBX v2.22 and earlier allows path traversal for file disclosure via the logprop?file=/.. substring.
CVE-2021-37439MEDIUM6.5NCH FlexiServer v6.00 suffers from a syslog?file=/.. path traversal vulnerability.
CVE-2021-37470MEDIUM5.4In NCH WebDictate v2.13, persistent Cross Site Scripting (XSS) exists in the Recipient Name field. An authenticated user...
CVE-2021-37469MEDIUM6.5In NCH WebDictate v2.13 and earlier, authenticated users can abuse logprop?file=/.. path traversal to read files on the ...
CVE-2021-37468LOW3.3NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration file...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now