2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29239HIGH7.8CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries wit...
CVE-2021-29238HIGH8.8CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF).
CVE-2021-29369CRITICAL9.8The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot command...
CVE-2021-28860CRITICAL9.1In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the muta...
CVE-2021-25631HIGH8.8In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist...
CVE-2021-31996HIGH7.5An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. There is a double free in merge_sort::mer...
CVE-2021-28359MEDIUM6.1The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects...
CVE-2021-31935MEDIUM6.1OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandl...
CVE-2021-31934MEDIUM6.1OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that ...
CVE-2021-31792MEDIUM5.4XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
CVE-2021-31933HIGH7.2A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a paramete...
CVE-2021-21547MEDIUM6.7Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerabili...
CVE-2021-21544LOW2.7Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated ma...
CVE-2021-21543MEDIUM4.8Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities. A remote auth...
CVE-2021-21542MEDIUM4.8Dell EMC iDRAC9 versions prior to 4.40.10.00 contain multiple stored cross-site scripting vulnerabilities. A remote auth...
CVE-2021-21541MEDIUM6.1Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a DOM-based cross-site scripting vulnerability. A remote unauthenti...
CVE-2021-21540HIGH8.1Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a stack-based overflow vulnerability. A remote authenticated attack...
CVE-2021-21539HIGH7.1Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. ...
CVE-2021-21531HIGH7.8Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticat...
CVE-2021-21530HIGH8.8Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authent...
CVE-2021-21507CRITICAL9.8Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versi...
CVE-2021-21233HIGH8.8Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially...
CVE-2021-21232HIGH8.8Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap...
CVE-2021-21231HIGH8.8Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially explo...
CVE-2021-21230HIGH8.8Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corrup...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now