2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20414MEDIUM4.9IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly l...
CVE-2021-33807HIGH7.5Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.
CVE-2021-33037MEDIUM5.3Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-enco...
CVE-2021-30640MEDIUM6.5A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user n...
CVE-2021-30639HIGH7.5A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part...
CVE-2021-36383MEDIUM4.3Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by mod...
CVE-2021-36382LOW3.7Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-t...
CVE-2021-32688HIGH8.8Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens...
CVE-2021-32680LOW3.3Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Ne...
CVE-2021-26088CRITICAL9.6An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user t...
CVE-2021-24015HIGH8.8An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of Fo...
CVE-2021-24013MEDIUM6.5Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unau...
CVE-2021-36377HIGH7.5Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
CVE-2021-32679HIGH8.8Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, fi...
CVE-2021-32678MEDIUM5.3Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ra...
CVE-2021-26090HIGH7.5A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 a...
CVE-2021-26089HIGH7.8An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitra...
CVE-2021-35064CRITICAL9.8KramerAV VIAWare, all tested versions, allow privilege escalation through misconfiguration of sudo. Sudoers permits runn...
CVE-2021-30129MEDIUM6.5A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error....
CVE-2021-3547HIGH7.4OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authenticatio...
CVE-2021-35037MEDIUM6.1Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their...
CVE-2021-27293HIGH7.5RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (R...
CVE-2021-22921HIGH7.8Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions...
CVE-2021-22918MEDIUM5.3Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to conver...
CVE-2021-22917MEDIUM6.5Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in T...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now