2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-33926HIGH8.8An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5....
CVE-2021-33391CRITICAL9.8An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() funct...
CVE-2021-33237Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. Consult IDs: CVE-2021-36686. Reason: This candidate is a duplicate of...
CVE-2021-33226CRITICAL9.8Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func vari...
CVE-2021-32441HIGH7.5SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive informat...
CVE-2021-32419MEDIUM5.3An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm...
CVE-2021-32163CRITICAL9.8Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorizatio...
CVE-2021-32142HIGH7.8Buffer Overflow vulnerability in LibRaw linux/unix v0.20.0 allows attacker to escalate privileges via the LibRaw_buffer_...
CVE-2021-43529CRITICAL9.8Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/M...
CVE-2021-23980MEDIUM6.1A mutation XSS affects users calling bleach.clean with all of: svg or math in the allowed tags p or br in allowed tags s...
CVE-2021-33104MEDIUM5.5Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potential...
CVE-2021-0187HIGH8.2Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially ena...
CVE-2021-43074MEDIUM4.3An improper verification of cryptographic signature vulnerability [CWE-347] in FortiWeb 6.4 all versions, 6.3.16 and bel...
CVE-2021-42761CRITICAL9.8A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions...
CVE-2021-42756CRITICAL9.8Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 a...
CVE-2021-40555MEDIUM5.4Cross site scripting (XSS) vulnerability in flatCore-CMS 2.2.15 allows attackers to execute arbitrary code via descripti...
CVE-2021-38239HIGH7.5SQL Injection vulnerability in dataease before 1.2.0, allows attackers to gain sensitive information via the orders para...
CVE-2021-34117HIGH7.5SQL Injection vulnerability in SEO Panel 4.9.0 in api/user.api.php in function getUserName in the username parameter, al...
CVE-2021-33925CRITICAL9.8SQL Injection vulnerability in nitinparashar30 cms-corephp through commit bdabe52ef282846823bda102728a35506d0ec8f9 (May ...
CVE-2021-33396MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other inf...
CVE-2021-33304CRITICAL9.8Double Free vulnerability in virtualsquare picoTCP v1.7.0 and picoTCP-NG v2.1 in modules/pico_fragments.c in function pi...
CVE-2021-46023HIGH7.5An Untrusted Pointer Dereference was discovered in function mrb_vm_exec in mruby before 3.1.0-rc. The vulnerability caus...
CVE-2021-42793Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2021-42792Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2021-41064Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now