2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26918CRITICAL9.8The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send ...
CVE-2021-3294MEDIUM5.4CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a co...
CVE-2021-26917MEDIUM5.5PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted...
CVE-2021-26916MEDIUM6.1In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary ...
CVE-2021-26915HIGH8.1NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code ...
CVE-2021-26914HIGH8.1NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code ...
CVE-2021-26913HIGH8.1NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code ...
CVE-2021-26912HIGH8.1NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code ...
CVE-2021-25913CRITICAL9.8Prototype pollution vulnerability in 'set-or-get' version 1.0.0 through 1.2.10 allows an attacker to cause a denial of s...
CVE-2021-22502CRITICAL9.8Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The...
CVE-2021-21306HIGH7.5Marked is an open-source markdown parser and compiler (npm package "marked"). In marked from version 1.1.1 and before ve...
CVE-2021-26576HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injec...
CVE-2021-26530CRITICAL9.1The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 (compiled with OpenSSL support) is vulnerable to remote OO...
CVE-2021-26529CRITICAL9.1The mg_tls_init function in Cesanta Mongoose HTTPS server 7.0 and 6.7-6.18 (compiled with mbedTLS support) is vulnerable...
CVE-2021-26528CRITICAL9.1The mg_http_serve_file function in Cesanta Mongoose HTTP server 7.0 is vulnerable to remote OOB write attack via connect...
CVE-2021-26222HIGH8.1The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the ...
CVE-2021-26221HIGH8.1The ezxml_new function in ezXML 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting the ...
CVE-2021-26220HIGH8.1The ezxml_toxml function in ezxml 0.8.6 and earlier is vulnerable to OOB write when opening XML file after exhausting th...
CVE-2021-26910HIGH7Firejail before 0.9.64.4 allows attackers to bypass intended access restrictions because there is a TOCTOU race conditio...
CVE-2021-26905MEDIUM6.51Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure ...
CVE-2021-26577HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-26575HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversa...
CVE-2021-26574HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a path traversa...
CVE-2021-26573HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-25172HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injec...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now