2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23341HIGH7.5The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc,...
CVE-2021-23340HIGH7.1This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAct...
CVE-2021-20446MEDIUM5.4IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2021-20445MEDIUM6.5IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of...
CVE-2021-20444MEDIUM6.1IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embe...
CVE-2021-20443HIGH8.8IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is ou...
CVE-2021-20354HIGH7.5IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker co...
CVE-2021-27378CRITICAL9.8An issue was discovered in the rand_core crate before 0.6.2 for Rust. Because read_u32_into and read_u64_into mishandle ...
CVE-2021-27377CRITICAL9.8An issue was discovered in the yottadb crate before 1.2.0 for Rust. For some memory-allocation patterns, ydb_subscript_n...
CVE-2021-27376CRITICAL9.8An issue was discovered in the nb-connect crate before 1.0.3 for Rust. It may have invalid memory access for certain ver...
CVE-2021-27124MEDIUM6.5SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated ...
CVE-2021-27375MEDIUM5.3Traefik before 2.4.5 allows the loading of IFRAME elements from other domains.
CVE-2021-27138HIGH7.8The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
CVE-2021-27097HIGH7.8The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.
CVE-2021-27374HIGH7.5VertiGIS WebOffice 10.7 SP1 before patch20210202 and 10.8 SP1 before patch20210207 allows attackers to achieve "Zugriff ...
CVE-2021-26720HIGH7.8avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-d...
CVE-2021-3396HIGH8.8OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through...
CVE-2021-27367HIGH7.5Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow D...
CVE-2021-26911HIGH7.4core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.
CVE-2021-1416MEDIUM4.3Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot...
CVE-2021-1412MEDIUM6.5Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot...
CVE-2021-1378HIGH7.5A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker ...
CVE-2021-1372MEDIUM5.5A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticate...
CVE-2021-1366HIGH7.8A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c...
CVE-2021-1351MEDIUM6.1A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to co...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now