2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29450MEDIUM4.3Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes passwo...
CVE-2021-21405HIGH7.5Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library m...
CVE-2021-29447MEDIUM6.5Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing iss...
CVE-2021-29432MEDIUM5.7Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the ...
CVE-2021-29431MEDIUM6.5Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due t...
CVE-2021-29430HIGH7.5Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. ...
CVE-2021-30245HIGH8.8The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The ...
CVE-2021-31402HIGH7.5The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulner...
CVE-2021-28055MEDIUM6.5An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, whi...
CVE-2021-29433MEDIUM4.3Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some param...
CVE-2021-26582MEDIUM6.1A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0...
CVE-2021-3243MEDIUM6.1Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet ...
CVE-2021-30138Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-29448HIGH8.8Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the P...
CVE-2021-27112CRITICAL9.8LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php duri...
CVE-2021-31229MEDIUM6.5An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handli...
CVE-2021-20288HIGH7.2An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY...
CVE-2021-3487Rejected reason: Non Security Issue. See the binutils security policy for more details, https://sourceware.org/cgit/binu...
CVE-2021-30209MEDIUM6.5Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background witho...
CVE-2021-28549HIGH7.8Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability whe...
CVE-2021-28548HIGH7.8Adobe Photoshop versions 21.2.6 (and earlier) and 22.3 (and earlier) are affected by a Buffer Overflow vulnerability whe...
CVE-2021-28242HIGH8.8SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat...
CVE-2021-27673MEDIUM4.8Cross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remot...
CVE-2021-27672MEDIUM4.9SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers t...
CVE-2021-21100HIGH7.8Adobe Digital Editions version 4.5.11.187245 (and earlier) is affected by a Privilege Escalation vulnerability during in...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now