2021 CVE Vulnerabilities

23,464 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26095HIGH8.8The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 thr...
CVE-2021-24022MEDIUM4.4A buffer overflow vulnerability in FortiAnalyzer CLI 6.4.5 and below, 6.2.7 and below, 6.0.x and FortiManager CLI 6.4.5 ...
CVE-2021-22125HIGH7.2An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow ...
CVE-2021-36980MEDIUM5.5Open vSwitch (aka openvswitch) 2.11.0 through 2.15.0 has a use-after-free in decode_NXAST_RAW_ENCAP (called from ofpact_...
CVE-2021-36979MEDIUM5.5Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb...
CVE-2021-36978MEDIUM5.5QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from...
CVE-2021-36977MEDIUM6.5matio (aka MAT File I/O Library) 1.5.20 and 1.5.21 has a heap-based buffer overflow in H5MM_memcpy (called from H5MM_mal...
CVE-2021-36976MEDIUM6.5libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
CVE-2021-35054HIGH7.5Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON file...
CVE-2021-26083MEDIUM5.4Export HTML Report in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6...
CVE-2021-26082MEDIUM5.4The XML Export in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, an...
CVE-2021-26081MEDIUM5.3REST API in Atlassian Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before 8.13.6, and from...
CVE-2021-32774MEDIUM5.4DataDump is a MediaWiki extension that provides dumps of wikis. Prior to commit 67a82b76e186925330b89ace9c5fd893a300830b...
CVE-2021-32773HIGH7.5Racket is a general-purpose programming language and an ecosystem for language-oriented programming. In versions prior t...
CVE-2021-3135MEDIUM6.1An issue was discovered in the tagDiv Newspaper theme 10.3.9.1 for WordPress. It allows XSS via the wp-admin/admin-ajax....
CVE-2021-32760MEDIUM6.3containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and ext...
CVE-2021-34618MEDIUM6.5A remote denial of service (DoS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in versi...
CVE-2021-34617MEDIUM6.1A remote cross-site scripting (XSS) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve...
CVE-2021-31590HIGH8.8PwnDoc all versions until 0.4.0 (2021-08-23) has incorrect JSON Webtoken handling, leading to incorrect access control. ...
CVE-2021-34821MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in AAT Novus Management System through 1.51.2. The WebUI has wrong HTTP ...
CVE-2021-34820HIGH7.5Web Path Directory Traversal in the Novus HTTP Server. The Novus HTTP Server is affected by the Directory Traversal for ...
CVE-2021-36799HIGH8.8KNX ETS5 through 5.7.6 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local use...
CVE-2021-36797MEDIUM6.8In Victron Energy Venus OS through 2.72, root access is granted by default to anyone with physical access to the device....
CVE-2021-34676HIGH7.5Basix NEX-Forms through 7.8.7 allows authentication bypass for Excel report generation.
CVE-2021-34675HIGH7.5Basix NEX-Forms through 7.8.7 allows authentication bypass for stored PDF reports.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now