2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23838MEDIUM4.8An issue was discovered in flatCore before 2.0.0 build 139. A reflected XSS vulnerability was identified in the media_fi...
CVE-2021-23837MEDIUM6.5An issue was discovered in flatCore before 2.0.0 build 139. A time-based blind SQL injection was identified in the selec...
CVE-2021-23836MEDIUM4.8An issue was discovered in flatCore before 2.0.0 build 139. A stored XSS vulnerability was identified in the prefs_smtp_...
CVE-2021-23835MEDIUM4.9An issue was discovered in flatCore before 2.0.0 build 139. A local file disclosure vulnerability was identified in the ...
CVE-2021-22132MEDIUM4.8Elasticsearch versions 7.7.0 to 7.10.1 contain an information disclosure flaw in the async search API. Users who execute...
CVE-2021-21261HIGH8.8Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. A bug was discovere...
CVE-2021-21722MEDIUM4.4A ZTE Smart STB is impacted by an information leak vulnerability. The device did not fully verify the log, so attackers ...
CVE-2021-24122MEDIUM5.9When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9...
CVE-2021-23926CRITICAL9.1The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from maliciou...
CVE-2021-20618CRITICAL9.8Privilege chaining vulnerability in acmailer ver. 4.0.2 and earlier, and acmailer DB ver. 1.1.4 and earlier allows remot...
CVE-2021-20617CRITICAL9.8Improper access control vulnerability in acmailer ver. 4.0.1 and earlier, and acmailer DB ver. 1.1.3 and earlier allows ...
CVE-2021-3138HIGH7.5In Discourse 2.7.0 through beta1, a rate-limit bypass leads to a bypass of the 2FA requirement for certain forms.
CVE-2021-21013HIGH8.1Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc...
CVE-2021-21012MEDIUM5.3Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc...
CVE-2021-21011HIGH7Adobe Captivate 2019 version 11.5.1.499 (and earlier) is affected by an uncontrolled search path element vulnerability t...
CVE-2021-21010HIGH7InCopy version 15.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could resu...
CVE-2021-21009HIGH8.6Adobe Campaign Classic Gold Standard 10 (and earlier), 20.3.1 (and earlier), 20.2.3 (and earlier), 20.1.3 (and earlier),...
CVE-2021-21008HIGH7Adobe Animate version 21.0 (and earlier) is affected by an uncontrolled search path element that could result in arbitra...
CVE-2021-21007HIGH7Adobe Illustrator version 25.0 (and earlier) is affected by an uncontrolled search path element that could result in arb...
CVE-2021-21006HIGH8.6Adobe Photoshop version 22.1 (and earlier) is affected by a heap buffer overflow vulnerability when handling a specially...
CVE-2021-1360HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2021-1311MEDIUM5.4A vulnerability in the reclaim host role feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an ...
CVE-2021-1310MEDIUM4.7A vulnerability in the web-based management interface of Cisco Webex Meetings could allow an unauthenticated, remote att...
CVE-2021-1307HIGH7.2Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W...
CVE-2021-1267MEDIUM4.3A vulnerability in the dashboard widget of Cisco Firepower Management Center (FMC) Software could allow an authenticated...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now