2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29998CRITICAL9.8An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.
CVE-2021-29997MEDIUM5.3An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on...
CVE-2021-28973MEDIUM4.9The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input dat...
CVE-2021-21731HIGH8.1A CSRF vulnerability exists in the management page of a ZTE product.The vulnerability is caused because the management p...
CVE-2021-21730CRITICAL9.8A ZTE product is impacted by improper access control vulnerability. The attacker could exploit this vulnerability to acc...
CVE-2021-21729MEDIUM6.5Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perfo...
CVE-2021-30176CRITICAL9.8The ZEROF Expert pro/2.0 application for mobile devices allows SQL Injection via the Authorization header to the /v2/dev...
CVE-2021-30175CRITICAL9.8ZEROF Web Server 1.0 (April 2021) allows SQL Injection via the /HandleEvent endpoint for the login page.
CVE-2021-28421Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-21417. Reason: This candidate is a duplicate of ...
CVE-2021-22505CRITICAL9.8Escalation of privileges vulnerability in Micro Focus Operations Agent, affects versions 12.0x, 12.10, 12.11, 12.12, 12....
CVE-2021-28647HIGH7.8Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an at...
CVE-2021-28646MEDIUM5.5An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could al...
CVE-2021-28645HIGH7.8An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 co...
CVE-2021-25253HIGH7.8An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP...
CVE-2021-25250HIGH7.8An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP...
CVE-2021-29943CRITICAL9.1When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/p...
CVE-2021-29425MEDIUM4.8In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "/...
CVE-2021-29262HIGH7.5When starting Apache Solr versions prior to 8.8.2, configured with the SaslZkACLProvider or VMParamsAllAndReadonlyDigest...
CVE-2021-27905CRITICAL9.8The ReplicationHandler (normally registered at "/replication" under a Solr core) in Apache Solr has a "masterUrl" (also ...
CVE-2021-29054HIGH8.8Certain Papoo products are affected by: Cross Site Request Forgery (CSRF) in the admin interface. This affects Papoo CMS...
CVE-2021-29003CRITICAL9.8Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter...
CVE-2021-28938MEDIUM4.3Siren Federate before 6.8.14-10.3.9, 6.9.x through 7.6.x before 7.6.2-20.2, 7.7.x through 7.9.x before 7.9.3-21.6, 7.10....
CVE-2021-30637MEDIUM5.4htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
CVE-2021-30503CRITICAL9.8The unofficial GLSL Linting extension before 1.4.0 for Visual Studio Code allows remote code execution via a crafted gls...
CVE-2021-30044MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now