2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-28583MEDIUM4.2Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of S...
CVE-2021-28576MEDIUM4.3Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially c...
CVE-2021-28575MEDIUM4.3Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially c...
CVE-2021-28574MEDIUM4.3Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially c...
CVE-2021-28573MEDIUM6.5Adobe Animate version 21.0.5 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially c...
CVE-2021-28570HIGH8.6Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unau...
CVE-2021-28563MEDIUM6.5Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by an Improper Auth...
CVE-2021-28562HIGH8.8Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and e...
CVE-2021-28556MEDIUM4.8Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a DOM-based Cros...
CVE-2021-21102HIGH8.8Adobe Illustrator version 25.2 (and earlier) is affected by a Path Traversal vulnerability when parsing a specially craf...
CVE-2021-21101HIGH8.8Adobe Illustrator version 25.2 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a speciall...
CVE-2021-21099HIGH8.8Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted fil...
CVE-2021-21098HIGH8.8Adobe InDesign version 16.0 (and earlier) is affected by an Out-of-bounds Write vulnerability when parsing a crafted fil...
CVE-2021-21090HIGH8.8Adobe InCopy version 16.0 (and earlier) is affected by an path traversal vulnerability when parsing a crafted file. An u...
CVE-2021-21084MEDIUM6.1AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are a...
CVE-2021-21083HIGH7.5AEM's Cloud Service offering, as well as versions 6.5.7.0 (and below), 6.4.8.3 (and below) and 6.3.3.8 (and below) are a...
CVE-2021-33515MEDIUM4.8The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can...
CVE-2021-31337CRITICAL9.8The Telnet service of the SIMATIC HMI Comfort Panels system component in affected products does not require authenticati...
CVE-2021-35514CRITICAL9.8Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
CVE-2021-32496MEDIUM5.3SICK Visionary-S CX up version 5.21.2.29154R are vulnerable to an Inadequate Encryption Strength vulnerability concernin...
CVE-2021-29157MEDIUM5.5Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authen...
CVE-2021-20100MEDIUM6.7Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities whi...
CVE-2021-20099MEDIUM6.7Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities whi...
CVE-2021-23399CRITICAL9.8This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function, ...
CVE-2021-20751MEDIUM6.1Cross-site scripting vulnerability in EC-CUBE EC-CUBE 4.0.0 to 4.0.5-p1 (EC-CUBE 4 series) allows a remote attacker to i...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now