2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20549 | MEDIUM | 5.4 | 0.5% | Apr 27, 2021 | IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2021-20448 | MEDIUM | 5.4 | 0.5% | Apr 27, 2021 | IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2021-3464 | HIGH | 7.8 | 0.3% | Apr 27, 2021 | A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privil... |
| CVE-2021-3451 | MEDIUM | 5.5 | 0.2% | Apr 27, 2021 | A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow conf... |
| CVE-2021-30642 | CRITICAL | 9.8 | 2.7% | Apr 27, 2021 | An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior... |
| CVE-2021-28269 | HIGH | 8.8 | 1.9% | Apr 27, 2021 | Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users gr... |
| CVE-2021-28271 | HIGH | 8.8 | 1.9% | Apr 27, 2021 | Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an a... |
| CVE-2021-22664 | HIGH | 7.8 | 1.6% | Apr 27, 2021 | CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds write, which may allow an attacker to execute arb... |
| CVE-2021-22660 | HIGH | 7.8 | 2.0% | Apr 27, 2021 | CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbi... |
| CVE-2021-27480 | CRITICAL | 9.8 | 1.3% | Apr 27, 2021 | Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may al... |
| CVE-2021-28125 | MEDIUM | 6.1 | 63.8% | Apr 27, 2021 | Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not ch... |
| CVE-2021-20715 | MEDIUM | 4.3 | 0.9% | Apr 27, 2021 | Improper access control vulnerability in Hot Pepper Gourmet App for Android ver.4.111.0 and earlier, and for iOS ver.4.1... |
| CVE-2021-20714 | MEDIUM | 6.5 | 2.6% | Apr 27, 2021 | Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administra... |
| CVE-2021-31826 | HIGH | 7.5 | 2.0% | Apr 27, 2021 | Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery ... |
| CVE-2021-31671 | HIGH | 7.5 | 0.7% | Apr 27, 2021 | pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema... |
| CVE-2021-30635 | MEDIUM | 5.3 | 1.8% | Apr 27, 2021 | Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that... |
| CVE-2021-30165 | HIGH | 8.1 | 1.1% | Apr 27, 2021 | The default administrator account & password of the EDIMAX wireless network camera is hard-coded. Remote attackers can d... |
| CVE-2021-29474 | MEDIUM | 5.8 | 1.6% | Apr 26, 2021 | HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md... |
| CVE-2021-31784 | HIGH | 7.8 | 0.9% | Apr 26, 2021 | An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Drawings SDK before 20... |
| CVE-2021-31783 | HIGH | 7.5 | 0.6% | Apr 26, 2021 | show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the fi... |
| CVE-2021-31646 | CRITICAL | 9.8 | 1.3% | Apr 26, 2021 | Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected compone... |
| CVE-2021-29475 | CRITICAL | 10 | 1.2% | Apr 26, 2021 | HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbi... |
| CVE-2021-29473 | LOW | 2.5 | 1.7% | Apr 26, 2021 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2021-22669 | HIGH | 8.8 | 1.2% | Apr 26, 2021 | Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA V... |
| CVE-2021-29694 | HIGH | 7.5 | 0.7% | Apr 26, 2021 | IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now