2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20549MEDIUM5.4IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2021-20448MEDIUM5.4IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2021-3464HIGH7.8A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privil...
CVE-2021-3451MEDIUM5.5A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow conf...
CVE-2021-30642CRITICAL9.8An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior...
CVE-2021-28269HIGH8.8Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users gr...
CVE-2021-28271HIGH8.8Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an a...
CVE-2021-22664HIGH7.8CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds write, which may allow an attacker to execute arb...
CVE-2021-22660HIGH7.8CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbi...
CVE-2021-27480CRITICAL9.8Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may al...
CVE-2021-28125MEDIUM6.1Apache Superset up to and including 1.0.1 allowed for the creation of an external URL that could be malicious. By not ch...
CVE-2021-20715MEDIUM4.3Improper access control vulnerability in Hot Pepper Gourmet App for Android ver.4.111.0 and earlier, and for iOS ver.4.1...
CVE-2021-20714MEDIUM6.5Directory traversal vulnerability in WP Fastest Cache versions prior to 0.9.1.7 allows a remote attacker with administra...
CVE-2021-31826HIGH7.5Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery ...
CVE-2021-31671HIGH7.5pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema...
CVE-2021-30635MEDIUM5.3Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that...
CVE-2021-30165HIGH8.1The default administrator account & password of the EDIMAX wireless network camera is hard-coded. Remote attackers can d...
CVE-2021-29474MEDIUM5.8HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker can read arbitrary `.md...
CVE-2021-31784HIGH7.8An out-of-bounds write vulnerability exists in the file-reading procedure in Open Design Alliance Drawings SDK before 20...
CVE-2021-31783HIGH7.5show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the fi...
CVE-2021-31646CRITICAL9.8Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected compone...
CVE-2021-29475CRITICAL10HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbi...
CVE-2021-29473LOW2.5Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2021-22669HIGH8.8Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA V...
CVE-2021-29694HIGH7.5IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now