2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27940MEDIUM6.1resources/public/js/orchestrator.js in openark orchestrator before 3.2.4 allows XSS via the orchestrator-msg parameter.
CVE-2021-27935HIGH7.5An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their...
CVE-2021-27931CRITICAL9.1LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControl...
CVE-2021-21314MEDIUM4.8GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana...
CVE-2021-21313MEDIUM6.1GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana...
CVE-2021-21312MEDIUM4.8GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana...
CVE-2021-27839MEDIUM4.4A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform ...
CVE-2021-22884HIGH7.5Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “...
CVE-2021-22883HIGH7.5Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connecti...
CVE-2021-22878MEDIUM4.8Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `O...
CVE-2021-22877MEDIUM6.5A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users exter...
CVE-2021-22681CRITICAL9.8Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key ...
CVE-2021-22188MEDIUM5.3An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab we...
CVE-2021-22182MEDIUM5.4An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS ...
CVE-2021-21978CRITICAL9.8VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val...
CVE-2021-27927HIGH8.8In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0...
CVE-2021-22683HIGH7.8Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowi...
CVE-2021-22670HIGH7.8An uninitialized pointer may be exploited in Fatek FvDesigner Version 1.5.76 and prior while the application is processi...
CVE-2021-22666HIGH7.8Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a stack-based buffer overflow while project files are being p...
CVE-2021-22662HIGH7.8A use after free issue has been identified in Fatek FvDesigner Version 1.5.76 and prior in the way the application proce...
CVE-2021-22638HIGH7.8Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds read while processing project files, allowin...
CVE-2021-21979HIGH7.3In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r1...
CVE-2021-20442HIGH7.5IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for i...
CVE-2021-20441MEDIUM5.9IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi...
CVE-2021-20233HIGH8.2A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calc...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now