2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32720MEDIUM5.3Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, par...
CVE-2021-35525MEDIUM5.3PostSRSd before 1.11 allows a denial of service (subprocess hang) if Postfix sends certain long data fields such as mult...
CVE-2021-35523HIGH7.8Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege es...
CVE-2021-34254MEDIUM6.1Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
CVE-2021-34187CRITICAL9.8main/inc/ajax/model.ajax.php in Chamilo through 1.11.14 allows SQL Injection via the searchField, filters, or filters2 p...
CVE-2021-32719MEDIUM4.8RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was di...
CVE-2021-29775MEDIUM5.4IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerabl...
CVE-2021-29751MEDIUM4.3IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authen...
CVE-2021-29693MEDIUM4.4IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial ...
CVE-2021-20574HIGH8.8IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP inject...
CVE-2021-20573MEDIUM6.5IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bo...
CVE-2021-20572MEDIUM6.5IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper b...
CVE-2021-20494MEDIUM6.5IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bo...
CVE-2021-20413MEDIUM4.3IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed...
CVE-2021-3556Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2021-35456CRITICAL9.8Online Pet Shop We App 1.0 is vulnerable to remote SQL injection and shell upload
CVE-2021-32718MEDIUM5.4RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via ma...
CVE-2021-28623MEDIUM5.5Adobe Premiere Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An u...
CVE-2021-28597MEDIUM5.5Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An ...
CVE-2021-28588HIGH8.8Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafte...
CVE-2021-28579MEDIUM4.3Adobe Connect version 11.2.1 (and earlier) is affected by an Improper access control vulnerability that can lead to the ...
CVE-2021-28587LOW3.3After Effects versions 18.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclos...
CVE-2021-28586HIGH7.8After Effects version 18.0 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbit...
CVE-2021-28585MEDIUM5.3Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper inpu...
CVE-2021-28584HIGH7.2Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Path Traversal...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now