2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27876HIGH8.1An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc...
CVE-2021-26704HIGH8.8EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/too...
CVE-2021-26703CRITICAL9.8EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input t...
CVE-2021-26702MEDIUM6.1EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI.
CVE-2021-26476CRITICAL9.8EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
CVE-2021-26475MEDIUM6.1EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI.
CVE-2021-3332MEDIUM5.3WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
CVE-2021-27318MEDIUM6.1Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to in...
CVE-2021-27317MEDIUM6.1Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to in...
CVE-2021-21517HIGH7.2SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML pa...
CVE-2021-21515MEDIUM5.4Dell EMC SourceOne, versions 7.2SP10 and prior, contain a Stored Cross-Site Scripting vulnerability. A remote low privil...
CVE-2021-25914CRITICAL9.8Prototype pollution vulnerability in 'object-collider' versions 1.0.0 through 1.0.3 allows attacker to cause a denial of...
CVE-2021-22114MEDIUM5.3Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write...
CVE-2021-25833CRITICAL9.8A file extension handling issue was found in [server] module of ONLYOFFICE DocumentServer v4.2.0.71-v5.6.0.21. The file ...
CVE-2021-25832CRITICAL9.8A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentSer...
CVE-2021-25831CRITICAL9.8A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker mus...
CVE-2021-25830CRITICAL9.8A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacke...
CVE-2021-25829HIGH7.5An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6....
CVE-2021-25329HIGH7The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5...
CVE-2021-25122HIGH7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0...
CVE-2021-27225MEDIUM5.4In Dataiku DSS before 8.0.6, insufficient access control in the Jupyter notebooks integration allows users (who have cod...
CVE-2021-27132CRITICAL9.8SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via...
CVE-2021-3197CRITICAL9.8An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by...
CVE-2021-3151MEDIUM5.4i-doit before 1.16.0 is affected by Stored Cross-Site Scripting (XSS) issues that could allow remote authenticated attac...
CVE-2021-3148CRITICAL9.8An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now