2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20681MEDIUM5.4Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remo...
CVE-2021-20677LOW3.1UNIVERGE Aspire series PBX (UNIVERGE Aspire WX from 1.00 to 3.51, UNIVERGE Aspire UX from 1.00 to 9.70, UNIVERGE SV9100 ...
CVE-2021-28250HIGH7.8CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. W...
CVE-2021-28249HIGH8.8CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Obje...
CVE-2021-28248HIGH7.5CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts...
CVE-2021-28247MEDIUM5.4CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticat...
CVE-2021-28246HIGH7.8CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Obje...
CVE-2021-3153MEDIUM6.5HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users withi...
CVE-2021-3027MEDIUM6.5app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak t...
CVE-2021-3119HIGH7.5Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sq...
CVE-2021-27372CRITICAL9.8Realtek xPON RTL9601D SDK 1.9 stores passwords in plaintext which may allow attackers to possibly gain access to the dev...
CVE-2021-29098HIGH7.8Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ...
CVE-2021-29097HIGH7.8Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS...
CVE-2021-29095MEDIUM6.8Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and e...
CVE-2021-29094MEDIUM6.8Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier...
CVE-2021-29093MEDIUM6.8A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows a...
CVE-2021-29010MEDIUM4.8A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in th...
CVE-2021-29009MEDIUM4.8A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via archive.php in th...
CVE-2021-29008MEDIUM4.8A cross-site scripting (XSS) issue in SEO Panel 4.8.0 allows remote attackers to inject JavaScript via webmaster-tools.p...
CVE-2021-27454HIGH7.8The software performs an operation at a privilege level higher than the minimum level required, which creates new weakne...
CVE-2021-27452HIGH7.8The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these...
CVE-2021-27450HIGH7.8SSH server configuration file does not implement some best practices. This could lead to a weakening of the SSH protocol...
CVE-2021-27448HIGH7.8A miscommunication in the file system allows adversaries with access to the MU320E to escalate privileges on the MU320E ...
CVE-2021-27440CRITICAL9.8The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to ...
CVE-2021-27438HIGH8.8The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now