2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27891HIGH8.8SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected.
CVE-2021-26924MEDIUM6.1An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protecti...
CVE-2021-26923HIGH7.5An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the ...
CVE-2021-27208MEDIUM6.8When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when...
CVE-2021-20179HIGH8.1A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corres...
CVE-2021-27576HIGH7.5If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This is...
CVE-2021-28379HIGH8.8web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow...
CVE-2021-28378MEDIUM5.4Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.
CVE-2021-28375HIGH7.8An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not p...
CVE-2021-28374HIGH7.5The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon ...
CVE-2021-28373HIGH7.5The auth_internal plugin in Tiny Tiny RSS (aka tt-rss) before 2021-03-12 allows an attacker to log in via the OTP code w...
CVE-2021-28361HIGH7.5An issue was discovered in Storage Performance Development Kit (SPDK) before 20.01.01. If a PDU is sent to the iSCSI tar...
CVE-2021-20018MEDIUM4.9A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specif...
CVE-2021-20017HIGH8.8A post-authenticated command injection vulnerability in SonicWall SMA100 allows an authenticated attacker to execute OS ...
CVE-2021-28162MEDIUM6.1In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascr...
CVE-2021-28161MEDIUM6.1In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javasc...
CVE-2021-28092HIGH7.5The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression De...
CVE-2021-27290HIGH7.5ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression which is vulnerable to a denial of service. ...
CVE-2021-21518HIGH7.8Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business P...
CVE-2021-21726LOW2.3Some ZTE products have an input verification vulnerability in the diagnostic function interface. Due to insufficient ver...
CVE-2021-21085HIGH7.8Adobe Connect version 11.0.7 (and earlier) is affected by an Input Validation vulnerability in the export feature. An at...
CVE-2021-21082HIGH7.8Adobe Photoshop versions 21.2.5 (and earlier) and 22.2 (and earlier) are affected by a Memory Corruption vulnerability w...
CVE-2021-21080MEDIUM6.1Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attac...
CVE-2021-21079MEDIUM6.1Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attac...
CVE-2021-21078MEDIUM6.5Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now