2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27524MEDIUM6.1Cross Site Scripting (XSS) vulnerability in margox braft-editor version 2.3.8, allows remote attackers to execute arbitr...
CVE-2021-27523CRITICAL9.8An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sens...
CVE-2021-26505CRITICAL9.8Prototype pollution vulnerability in MrSwitch hello.js version 1.18.6, allows remote attackers to execute arbitrary code...
CVE-2021-26504HIGH7.5Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sens...
CVE-2021-25857HIGH7.2An issue was discovered in pcmt superMicro-CMS version 3.11, allows authenticated attackers to execute arbitrary code vi...
CVE-2021-25856MEDIUM4.9An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in ...
CVE-2021-25786MEDIUM5.3An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file ...
CVE-2021-41544HIGH7.8A vulnerability has been identified in Siemens Software Center (All versions < V3.0). A DLL Hijacking vulnerability coul...
CVE-2021-24916HIGH7.5The Qubely WordPress plugin before 1.8.6 allows unauthenticated user to send arbitrary e-mails to arbitrary addresses vi...
CVE-2021-31681HIGH7.8Deserialization of Untrusted Data vulnerability in yolo 3 allows attackers to execute arbitrary code via crafted yaml fi...
CVE-2021-31680HIGH7.8Deserialization of Untrusted Data vulnerability in yolo 5 allows attackers to execute arbitrary code via crafted yaml fi...
CVE-2021-31651MEDIUM4.8Cross Site Scripting (XSS) vulnerability in neofarg-cms 0.2.3 allows remoate attacker to run arbitrary code via the copy...
CVE-2021-4324MEDIUM6.5Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to rea...
CVE-2021-4323MEDIUM6.5Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who ...
CVE-2021-4322HIGH8.8Use after free in DevTools in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a ...
CVE-2021-4321MEDIUM4.3Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security polic...
CVE-2021-4320HIGH8.8Use after free in Blink in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the render...
CVE-2021-4319HIGH8.8Use after free in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to perform arbitrary read/write...
CVE-2021-4318HIGH8.8Object corruption in Blink in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit objec...
CVE-2021-4317HIGH8.8Use after free in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform arbitrary read/write...
CVE-2021-4316MEDIUM4.3Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browse...
CVE-2021-36580MEDIUM6.1Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the refere...
CVE-2021-39421MEDIUM6.1A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2021-35391HIGH7.2Server Side Request Forgery vulnerability found in Deskpro Support Desk v2021.21.6 allows attackers to execute arbitrary...
CVE-2021-39425MEDIUM6.1SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now