2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22916MEDIUM5.9In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installe...
CVE-2021-22515MEDIUM6.5Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in Net...
CVE-2021-26099MEDIUM4.9Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who...
CVE-2021-29105MEDIUM5.4A stored Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server Services Directory version 10.8.1 and below may ...
CVE-2021-29104MEDIUM6.1A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote u...
CVE-2021-29103MEDIUM6.1A reflected Cross Site Scripting (XXS) vulnerability in ArcGIS Server version 10.8.1 and below may allow a remote attack...
CVE-2021-29102CRITICAL9.1A Server-Side Request Forgery (SSRF) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote,...
CVE-2021-29107MEDIUM6.1A stored Cross Site Scripting (XXS) vulnerability in ArcGIS Server Manager version 10.8.1 and below may allow a remote u...
CVE-2021-29106MEDIUM6.1A reflected Cross Site Scripting (XSS) vulnerability in Esri ArcGIS Server version 10.8.1 and below may allow a remote a...
CVE-2021-35361MEDIUM4.8A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/links of dotCMS 21.05.1 allows attackers to execute...
CVE-2021-35360MEDIUM4.8A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/containers of dotCMS 21.05.1 allows attackers to ex...
CVE-2021-35358MEDIUM4.8A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attack...
CVE-2021-20024HIGH8.1Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a s...
CVE-2021-36371LOW3.7Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certificate requirem...
CVE-2021-36367HIGH8.1PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication resp...
CVE-2021-33214MEDIUM6.1In HMS Ewon eCatcher through 6.6.4, weak filesystem permissions could allow malicious users to access files that could l...
CVE-2021-32753MEDIUM6.5EdgeX Foundry is an open source project for building a common open framework for internet-of-things edge computing. A vu...
CVE-2021-26106HIGH7.8An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6....
CVE-2021-26100HIGH7.5A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthentic...
CVE-2021-24020CRITICAL9.8A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6....
CVE-2021-24007CRITICAL9.8Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow...
CVE-2021-22129HIGH8.8Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail befo...
CVE-2021-33795MEDIUM5.5Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 produce incorrect PDF document signatures because the certificat...
CVE-2021-33792HIGH7.8Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trail...
CVE-2021-3541MEDIUM6.5A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanis...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now