2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22848CRITICAL9.8HGiga MailSherlock contains a SQL Injection. Remote attackers can inject SQL syntax and execute SQL commands in a URL pa...
CVE-2021-28681MEDIUM5.3Pion WebRTC before 3.0.15 didn't properly tear down the DTLS Connection when certificate verification failed. The PeerCo...
CVE-2021-28667HIGH7.5StackStorm before 3.4.1, in some situations, has an infinite loop that consumes all available memory and disk space. Thi...
CVE-2021-20678HIGH8.8SQL injection vulnerability in the Paid Memberships Pro versions prior to 2.5.6 allows remote authenticated attackers to...
CVE-2021-20676MEDIUM4.3M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) ve...
CVE-2021-20675MEDIUM6.5M-System DL8 series (type A (DL8-A) versions prior to Ver3.0, type B (DL8-B) versions prior to Ver3.0, type C (DL8-C) ve...
CVE-2021-20634MEDIUM4.3Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to ...
CVE-2021-20633MEDIUM4.3Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to byp...
CVE-2021-20632MEDIUM4.3Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers...
CVE-2021-20631MEDIUM6.5Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to...
CVE-2021-20630MEDIUM4.3Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers...
CVE-2021-20629MEDIUM6.1Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbi...
CVE-2021-20628MEDIUM6.1Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a...
CVE-2021-20627MEDIUM6.1Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a...
CVE-2021-20626MEDIUM6.5Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to by...
CVE-2021-20625MEDIUM4.3Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attack...
CVE-2021-20624MEDIUM6.5Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to...
CVE-2021-28660HIGH8.8rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyo...
CVE-2021-20200Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-27292HIGH7.5ua-parser-js >= 0.7.14, fixed in 0.7.24, uses a regular expression which is vulnerable to denial of service. If an attac...
CVE-2021-27291HIGH7.5In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. So...
CVE-2021-22860CRITICAL9.8EIC e-document system does not perform completed identity verification for sorting and filtering personnel data. The vul...
CVE-2021-22859CRITICAL9.8The users’ data querying function of EIC e-document system does not filter the special characters which resulted in remo...
CVE-2021-28650MEDIUM5.5autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Dire...
CVE-2021-3344HIGH8.8A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now