2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3604CRITICAL9.8Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injecti...
CVE-2021-32956MEDIUM6.1Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a m...
CVE-2021-32954MEDIUM6.5Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker t...
CVE-2021-23846MEDIUM5.9When using http protocol, the user password is transmitted as a clear text parameter for which it is possible to be obta...
CVE-2021-23845HIGH8.8This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. Thi...
CVE-2021-21997MEDIUM5.5VMware Tools for Windows (11.x.y prior to 11.3.0) contains a denial-of-service vulnerability in the VM3DMP driver. A mal...
CVE-2021-34815MEDIUM4.8CheckSec Canopy before 3.5.2 allows XSS attacks against the login page via the LOGIN_PAGE_DISCLAIMER parameter.
CVE-2021-26835MEDIUM6.1No filtering of cross-site scripting (XSS) payloads in the markdown-editor in Zettlr 1.8.7 allows attackers to perform r...
CVE-2021-26834MEDIUM5.4A cross-site scripting (XSS) vulnerability exists in Znote 0.5.2. An attacker can insert payloads, and the code executio...
CVE-2021-33577MEDIUM5.3An issue was discovered in Cleo LexiCom 5.5.0.0. The requirement for the sender of an AS2 message to identify themselves...
CVE-2021-33576CRITICAL9.8An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filenam...
CVE-2021-33347MEDIUM5.4An issue was discovered in JPress v3.3.0 and below. There are XSS vulnerabilities in the template module and tag managem...
CVE-2021-32536MEDIUM6.1The login page in the MCUsystem does not filter with special characters, which allows remote attackers can inject JavaSc...
CVE-2021-21669CRITICAL9.8Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity...
CVE-2021-34812HIGH7.5Use of hard-coded credentials vulnerability in php component in Synology Calendar before 2.4.0-0761 allows remote attack...
CVE-2021-34811MEDIUM4.3Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16...
CVE-2021-34810HIGH8.8Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remo...
CVE-2021-34809HIGH8.8Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management com...
CVE-2021-34808MEDIUM5.3Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remo...
CVE-2021-34553MEDIUM4.3Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files a...
CVE-2021-32693HIGH8.8Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability relate...
CVE-2021-32694MEDIUM5.5Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.15.1, a malicious application on the s...
CVE-2021-32426MEDIUM6.1In TrendNet TW100-S4W1CA 2.3.32, it is possible to inject arbitrary JavaScript into the router's web interface via the "...
CVE-2021-32424HIGH8.8In TrendNet TW100-S4W1CA 2.3.32, due to a lack of proper session controls, a threat actor could make unauthorized change...
CVE-2021-32695LOW3.3Nextcloud Android app is the Android client for Nextcloud. In versions prior to 3.16.1, a malicious app on the same devi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now