2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22735HIGH7.2Improper Verification of Cryptographic Signature vulnerability exists inhomeLYnk (Wiser For KNX) and spaceLYnk V2.60 and...
CVE-2021-22734HIGH7.2Improper Verification of Cryptographic Signature vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 an...
CVE-2021-22733HIGH7.8Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could...
CVE-2021-22732HIGH7.8Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could...
CVE-2021-22731CRITICAL9.8Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSES...
CVE-2021-22705HIGH7.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of ...
CVE-2021-22699HIGH7.5Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that co...
CVE-2021-33470CRITICAL9.8COVID19 Testing Management System 1.0 is vulnerable to SQL Injection via the admin panel.
CVE-2021-33469MEDIUM4.8COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.
CVE-2021-20492HIGH8.2IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection...
CVE-2021-20487CRITICAL9.1IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of ...
CVE-2021-20486MEDIUM6.5IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additio...
CVE-2021-33506HIGH7.5jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This c...
CVE-2021-33194HIGH7.5golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop)...
CVE-2021-25945CRITICAL9.8Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of servi...
CVE-2021-21986CRITICAL9.8The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Che...
CVE-2021-21985CRITICAL9.8The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual...
CVE-2021-33038HIGH7.5An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a privat...
CVE-2021-32457HIGH7.8Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vuln...
CVE-2021-22160CRITICAL9.8If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the...
CVE-2021-20178MEDIUM5.5A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by th...
CVE-2021-27676MEDIUM5.4Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Desc...
CVE-2021-26034MEDIUM6.5An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data downl...
CVE-2021-26033MEDIUM6.5An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX r...
CVE-2021-26032MEDIUM6.1An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now