2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43444HIGH7.5ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. Signed document download URLs can be f...
CVE-2021-24881HIGH7.5The Passster WordPress plugin before 3.5.5.9 does not properly check for password, as well as that the post to be viewed...
CVE-2021-24837MEDIUM5.4The Passster WordPress plugin before 3.5.5.8 does not escape the area parameter of its shortcode, which could allow user...
CVE-2021-33642MEDIUM5.5When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function.
CVE-2021-33641HIGH7.8When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses...
CVE-2021-39089MEDIUM6.5IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 could allow an authenticated user to obtain sensitive inform...
CVE-2021-39011MEDIUM4.9 IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.6.0 stores potentially sensitive information in log files that ...
CVE-2021-29368HIGH8.8Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 all...
CVE-2021-26644CRITICAL9.8SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mang...
CVE-2021-26642CRITICAL9.8When uploading an image file to a bulletin board developed with XpressEngine, a vulnerability in which an arbitrary file...
CVE-2021-37500HIGH8.1Directory traversal vulnerability in Reprise License Manager (RLM) web interface before 14.2BL4 in the diagnostics funct...
CVE-2021-37499MEDIUM6.5CRLF vulnerability in Reprise License Manager (RLM) web interface through 14.2BL4 in the password parameter in View Lice...
CVE-2021-37498MEDIUM6.5An SSRF issue was discovered in Reprise License Manager (RLM) web interface through 14.2BL4 that allows remote attackers...
CVE-2021-27782HIGH7.5HCL BigFix Mobile / Modern Client Management Admin and Config UI passwords can be brute-forced. User should be locked ou...
CVE-2021-37774HIGH8An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code...
CVE-2021-4314MEDIUM5.3It is possible to manipulate the JWT token without the knowledge of the JWT secret and authenticate without valid JWT to...
CVE-2021-33959HIGH7.5Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
CVE-2021-36630HIGH7.5DDOS reflection amplification vulnerability in eAut module of Ruckus Wireless SmartZone controller that allows remote at...
CVE-2021-32837HIGH7.5mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerab...
CVE-2021-36647MEDIUM4.7Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS ...
CVE-2021-46799Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-46796Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-46793Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-46761Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...
CVE-2021-26405Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes:...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now