2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3604 | CRITICAL | 9.8 | 1.6% | Jun 18, 2021 | Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injecti... |
| CVE-2021-32956 | MEDIUM | 6.1 | 0.7% | Jun 18, 2021 | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a m... |
| CVE-2021-32954 | MEDIUM | 6.5 | 2.1% | Jun 18, 2021 | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker t... |
| CVE-2021-23846 | MEDIUM | 5.9 | 0.5% | Jun 18, 2021 | When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obta... |
| CVE-2021-23845 | HIGH | 8.8 | 0.8% | Jun 18, 2021 | This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. Thi... |
| CVE-2021-21997 | MEDIUM | 5.5 | 0.5% | Jun 18, 2021 | VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A mal... |
| CVE-2021-34815 | MEDIUM | 4.8 | 0.8% | Jun 18, 2021 | CheckSec Canopy before 3.5.2 allows XSS attacks against the login page via the LOGIN_PAGE_DISCLAIMER parameter. |
| CVE-2021-26835 | MEDIUM | 6.1 | 1.3% | Jun 18, 2021 | No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform r... |
| CVE-2021-26834 | MEDIUM | 5.4 | 0.7% | Jun 18, 2021 | A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code executio... |
| CVE-2021-33577 | MEDIUM | 5.3 | 0.6% | Jun 18, 2021 | An issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves... |
| CVE-2021-33576 | CRITICAL | 9.8 | 1.5% | Jun 18, 2021 | An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filenam... |
| CVE-2021-33347 | MEDIUM | 5.4 | 0.5% | Jun 18, 2021 | An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag managem... |
| CVE-2021-32536 | MEDIUM | 6.1 | 0.8% | Jun 18, 2021 | The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaSc... |
| CVE-2021-21669 | CRITICAL | 9.8 | 25.7% | Jun 18, 2021 | Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity... |
| CVE-2021-34812 | HIGH | 7.5 | 1.1% | Jun 18, 2021 | Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attack... |
| CVE-2021-34811 | MEDIUM | 4.3 | 0.8% | Jun 18, 2021 | Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16... |
| CVE-2021-34810 | HIGH | 8.8 | 1.4% | Jun 18, 2021 | Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remo... |
| CVE-2021-34809 | HIGH | 8.8 | 1.9% | Jun 18, 2021 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management com... |
| CVE-2021-34808 | MEDIUM | 5.3 | 1.0% | Jun 18, 2021 | Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remo... |
| CVE-2021-34553 | MEDIUM | 4.3 | 3.7% | Jun 18, 2021 | Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files a... |
| CVE-2021-32693 | HIGH | 8.8 | 1.4% | Jun 17, 2021 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability relate... |
| CVE-2021-32694 | MEDIUM | 5.5 | 1.0% | Jun 17, 2021 | Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the s... |
| CVE-2021-32426 | MEDIUM | 6.1 | 0.8% | Jun 17, 2021 | In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "... |
| CVE-2021-32424 | HIGH | 8.8 | 0.4% | Jun 17, 2021 | In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session controls, a threat actor could make unauthorized change... |
| CVE-2021-32695 | LOW | 3.3 | 0.9% | Jun 17, 2021 | Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.16.1, a malicious app on the same devi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now