2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-35475MEDIUM5.4SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when e...
CVE-2021-32717HIGH7.5Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud...
CVE-2021-32716MEDIUM4.9Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidd...
CVE-2021-32713MEDIUM4.8Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in admin...
CVE-2021-32712MEDIUM5.3Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in ...
CVE-2021-35448HIGH7.8Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using...
CVE-2021-32711HIGH7.5Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vuln...
CVE-2021-32710HIGH7.5Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2....
CVE-2021-3500HIGH7.8A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via c...
CVE-2021-32709MEDIUM4.9Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users...
CVE-2021-32493HIGH7.8A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted...
CVE-2021-32492HIGH7.8A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via craft...
CVE-2021-32491HIGH7.8A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted dj...
CVE-2021-32490HIGH7.8A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu ...
CVE-2021-29777MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circum...
CVE-2021-29703HIGH7.5Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server termina...
CVE-2021-20579MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who...
CVE-2021-33004HIGH7.8The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied file...
CVE-2021-33002HIGH7.8Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbi...
CVE-2021-33000HIGH7.8Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perfor...
CVE-2021-32708HIGH8.1Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any ...
CVE-2021-21574HIGH7.5Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local acce...
CVE-2021-21573HIGH7.5Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local acce...
CVE-2021-21572HIGH7.5Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local acce...
CVE-2021-21571MEDIUM6.5Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper ce...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now