2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29239 | HIGH | 7.8 | 0.2% | May 3, 2021 | CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries wit... |
| CVE-2021-29238 | HIGH | 8.8 | 0.5% | May 3, 2021 | CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF). |
| CVE-2021-29369 | CRITICAL | 9.8 | 1.8% | May 3, 2021 | The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot command... |
| CVE-2021-28860 | CRITICAL | 9.1 | 2.0% | May 3, 2021 | In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the muta... |
| CVE-2021-25631 | HIGH | 8.8 | 4.2% | May 3, 2021 | In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist... |
| CVE-2021-31996 | HIGH | 7.5 | 1.0% | May 3, 2021 | An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. There is a double free in merge_sort::mer... |
| CVE-2021-28359 | MEDIUM | 6.1 | 14.4% | May 2, 2021 | The "origin" parameter passed to some of the endpoints like '/trigger' was vulnerable to XSS exploit. This issue affects... |
| CVE-2021-31935 | MEDIUM | 6.1 | 0.9% | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows XSS via a crafted distribution list (payload in the common name) that is mishandl... |
| CVE-2021-31934 | MEDIUM | 6.1 | 0.9% | Apr 30, 2021 | OX App Suite 7.10.4 and earlier allows XSS via a crafted contact object (payload in the position or company field) that ... |
| CVE-2021-31792 | MEDIUM | 5.4 | 0.9% | Apr 30, 2021 | XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field |
| CVE-2021-31933 | HIGH | 7.2 | 13.9% | Apr 30, 2021 | A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a paramete... |
| CVE-2021-21547 | MEDIUM | 6.7 | 0.1% | Apr 30, 2021 | Dell EMC Unity, UnityVSA, and Unity XT versions prior to 5.0.7.0.5.008 contain a plain-text password storage vulnerabili... |
| CVE-2021-21544 | LOW | 2.7 | 0.9% | Apr 30, 2021 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A remote authenticated ma... |
| CVE-2021-21543 | MEDIUM | 4.8 | 0.6% | Apr 30, 2021 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain multiple stored cross-site scripting vulnerabilities. A remote auth... |
| CVE-2021-21542 | MEDIUM | 4.8 | 0.4% | Apr 30, 2021 | Dell EMC iDRAC9 versions prior to 4.40.10.00 contain multiple stored cross-site scripting vulnerabilities. A remote auth... |
| CVE-2021-21541 | MEDIUM | 6.1 | 0.8% | Apr 30, 2021 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a DOM-based cross-site scripting vulnerability. A remote unauthenti... |
| CVE-2021-21540 | HIGH | 8.1 | 1.2% | Apr 30, 2021 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a stack-based overflow vulnerability. A remote authenticated attack... |
| CVE-2021-21539 | HIGH | 7.1 | 0.6% | Apr 30, 2021 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. ... |
| CVE-2021-21531 | HIGH | 7.8 | 0.7% | Apr 30, 2021 | Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticat... |
| CVE-2021-21530 | HIGH | 8.8 | 0.9% | Apr 30, 2021 | Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authent... |
| CVE-2021-21507 | CRITICAL | 9.8 | 0.5% | Apr 30, 2021 | Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versi... |
| CVE-2021-21233 | HIGH | 8.8 | 1.3% | Apr 30, 2021 | Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially... |
| CVE-2021-21232 | HIGH | 8.8 | 1.1% | Apr 30, 2021 | Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap... |
| CVE-2021-21231 | HIGH | 8.8 | 1.1% | Apr 30, 2021 | Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially explo... |
| CVE-2021-21230 | HIGH | 8.8 | 1.6% | Apr 30, 2021 | Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corrup... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now