2021 CVE Vulnerabilities

23,464 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29780MEDIUM4.7IBM Resilient OnPrem v41.1 of IBM Security SOAR could allow an authenticated user to perform actions that they should no...
CVE-2021-29707HIGH7.8IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to...
CVE-2021-20507MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-35449HIGH7.8The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below,...
CVE-2021-35043MEDIUM6.1OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected)...
CVE-2021-20110CRITICAL9.8Due to Manage Engine Asset Explorer Agent 1.0.34 not validating HTTPS certificates, an attacker on the network can stati...
CVE-2021-20109HIGH7.5Due to the Asset Explorer agent not validating HTTPS certificates, an attacker on the network can statically configure t...
CVE-2021-20108HIGH7.5Manage Engine Asset Explorer Agent 1.0.34 listens on port 9000 for incoming commands over HTTPS from Manage Engine Serve...
CVE-2021-34817MEDIUM6.1A Cross-Site Scripting (XSS) issue in the chat component of Etherpad 1.8.13 allows remote attackers to inject arbitrary ...
CVE-2021-32014MEDIUM5.5SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (CPU consumption) via a crafted .xl...
CVE-2021-32013MEDIUM5.5SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted ...
CVE-2021-32012MEDIUM5.5SheetJS and SheetJS Pro through 0.16.9 allows attackers to cause a denial of service (memory consumption) via a crafted ...
CVE-2021-3279MEDIUM6.1sz.chat version 4 allows injection of web scripts and HTML in the message box.
CVE-2021-31216HIGH8.1Siren Investigate before 11.1.1 contains a server side request forgery (SSRF) defect in the built-in image proxy route (...
CVE-2021-35968MEDIUM4.3The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly....
CVE-2021-35967MEDIUM5.3The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attack...
CVE-2021-35966MEDIUM6.1The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing...
CVE-2021-35965CRITICAL9.8The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the so...
CVE-2021-35964CRITICAL9.8The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remot...
CVE-2021-35963CRITICAL9.8The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which a...
CVE-2021-33501CRITICAL9.6Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.
CVE-2021-33027CRITICAL9.8Sylabs Singularity Enterprise through 1.6.2 has Insufficient Entropy in a nonce.
CVE-2021-24482MEDIUM4.8The Related Posts for WordPress plugin through 2.0.4 does not sanitise its heading_text and CSS settings, allowing high ...
CVE-2021-24453HIGH8.8The Include Me WordPress plugin through 1.2.1 is vulnerable to path traversal / local file inclusion, which can lead to ...
CVE-2021-24452MEDIUM6.1The W3 Total Cache WordPress plugin before 2.1.5 was affected by a reflected Cross-Site Scripting (XSS) issue within the...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now