2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26930HIGH7.8An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend,...
CVE-2021-27104CRITICAL9.8Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpo...
CVE-2021-27103CRITICAL9.8Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed vers...
CVE-2021-27102HIGH7.8Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version i...
CVE-2021-27101CRITICAL9.8Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root....
CVE-2021-27203MEDIUM5.5In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitr...
CVE-2021-20075HIGH7.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.
CVE-2021-20074HIGH8.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and ...
CVE-2021-20073HIGH8.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries.
CVE-2021-20072HIGH7.2Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an ...
CVE-2021-20071MEDIUM4.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via t...
CVE-2021-20070MEDIUM4.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via t...
CVE-2021-20069MEDIUM4.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via th...
CVE-2021-20068MEDIUM4.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via th...
CVE-2021-20067MEDIUM5.3Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authen...
CVE-2021-20066MEDIUM5.6JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious we...
CVE-2021-27237MEDIUM4.8The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/...
CVE-2021-21317MEDIUM5.3uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In u...
CVE-2021-21316HIGH7.8less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10.,...
CVE-2021-23841MEDIUM5.9The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer...
CVE-2021-23840HIGH7.5Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases...
CVE-2021-23839LOW3.7OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both S...
CVE-2021-21315HIGH7.8The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions t...
CVE-2021-20987HIGH8.6A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21tha...
CVE-2021-20986HIGH7.5A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may l...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now