2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22119HIGH7.5Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are...
CVE-2021-21871HIGH7.8A memory corruption vulnerability exists in the DMG File Format Handler functionality of PowerISO 7.9. A specially craft...
CVE-2021-20580MEDIUM4.3IBM Planning Analytics 2.0 could be vulnerable to cross-site request forgery (CSRF) which could allow an attacker to exe...
CVE-2021-20490MEDIUM5.5IBM Spectrum Protect Plus 10.1.0 through 10.1.8 could allow a local user to cause a denial of service due to insecure fi...
CVE-2021-20477MEDIUM5.4IBM Planning Analytics 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2021-20105MEDIUM6.1Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' p...
CVE-2021-20104HIGH8.1Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of ...
CVE-2021-20103MEDIUM6.1Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attac...
CVE-2021-20102HIGH8.8Machform prior to version 16 is vulnerable to cross-site request forgery due to a lack of CSRF tokens in place.
CVE-2021-20101MEDIUM6.1Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This ...
CVE-2021-32992CRITICAL9.8FATEK Automation WinProladder Versions 3.30 and prior do not properly restrict operations within the bounds of a memory ...
CVE-2021-32990CRITICAL9.8FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds read, which may allow an attack...
CVE-2021-32988CRITICAL9.8FATEK Automation WinProladder Versions 3.30 and prior are vulnerable to an out-of-bounds write, which may allow an attac...
CVE-2021-31516HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vector 35 Binary Ninja...
CVE-2021-31515HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Vector 35 Binary Ninja...
CVE-2021-31514HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto...
CVE-2021-31513HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto...
CVE-2021-31512HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto...
CVE-2021-31511HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto...
CVE-2021-31510HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto...
CVE-2021-31509HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto...
CVE-2021-31508HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto...
CVE-2021-31507HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Deskto...
CVE-2021-31506LOW3.3This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenText Brava...
CVE-2021-31505MEDIUM6.8This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now