2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-44016HIGH7.8A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), S...
CVE-2021-44000HIGH7.8A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), S...
CVE-2021-40363HIGH7.8A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS...
CVE-2021-40360HIGH8.8A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS...
CVE-2021-37205HIGH7.5A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200...
CVE-2021-37204HIGH7.5A vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC Drive Controller...
CVE-2021-37194HIGH7.5A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers...
CVE-2021-37185HIGH7.5A vulnerability has been identified in SIMATIC Drive Controller family (All versions >= V2.9.2 < V2.9.4), SIMATIC ET 200...
CVE-2021-46360HIGH8.8Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrar...
CVE-2021-46354HIGH7.5Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an information disclosure vuln...
CVE-2021-37852HIGH7.8ESET products for Windows allows untrusted process to impersonate the client of a pipe, which can be leveraged by attack...
CVE-2021-45326HIGH8.8Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especi...
CVE-2021-45325HIGH7.5Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.
CVE-2021-3835HIGH8.8Buffer overflow in usb device class. Zephyr versions >= v2.6.0 contain Heap-based Buffer Overflow (CWE-122). For more in...
CVE-2021-42833HIGH8.8A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenti...
CVE-2021-25108HIGH7.1The IP2Location Country Blocker WordPress plugin before 2.26.6 does not have CSRF check in the ip2location_country_block...
CVE-2021-25095HIGH7.1The IP2Location Country Blocker WordPress plugin before 2.26.5 does not have authorisation and CSRF checks in the ip2loc...
CVE-2021-24879HIGH8.8The SupportCandy WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any san...
CVE-2021-24839HIGH7.5The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX acti...
CVE-2021-46389HIGH7.5IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by ...
CVE-2021-46359HIGH7.5FISCO-BCOS release-3.0.0-rc2 contains a denial of service vulnerability. Some transactions may not be committed successf...
CVE-2021-43928HIGH8.8Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending...
CVE-2021-39280HIGH8.8Certain Korenix JetWave devices allow authenticated users to execute arbitrary code as root via /syscmd.asp. This affect...
CVE-2021-4154HIGH8.8A use-after-free flaw was found in cgroup1_parse_param in kernel/cgroup/cgroup-v1.c in the Linux kernel's cgroup v1 pars...
CVE-2021-44206HIGH7.3Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now