LiveActive security incident?Get immediate response
CVE archive

2021 CVE Archive

Browse CVE records published in 2021 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 22591 matching CVEs · Page 15 of 452.

Unknown · CVSS Not scored

CVE-2021-29041: Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before f...

Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (1) enabling Time-based One-time password (TOTP) on behalf of the other user or (2) modifying the other user's TOTP shared secret.

Published May 16, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-29040: The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 befo...

The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused attacks via crafted inputs.

Published May 16, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-29004: rConfig 3.9.6 is affected by SQL Injection.

rConfig 3.9.6 is affected by SQL Injection. A user must be authenticated to exploit the vulnerability. If --secure-file-priv in MySQL server is not set and the Mysql server is the same as rConfig, an attacker may successfully upload a webshell to the server and access it remotely.

Published Oct 11, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-28927: The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell th...

The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platform_win32.c via the accessibility_speak_windows function, which allows attackers who have write access on filesystems that are used by RetroArch to execute code via command injection using specially a crafted file and directory names.

Published Apr 7, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-28860: In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' thr...

In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the mutate() and merge() functions. The polluted attribute will be directly assigned to every object in the program. This will put the availability of the program at risk causing a potential denial of service (DoS).

Published May 3, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-25681: AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of dat...

AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager web servers to be used as DNS redirectors to tunnel arbitrary data over DNS. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.

Published Apr 20, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-25680: The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) i...

The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.

Published Apr 20, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-25679: The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (X...

The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only version 10.8.1 was able to be confirmed during primary research. NOTE: The affected appliances NetVanta 7060 and NetVanta 7100 are considered End of Life and as such this issue will not be patched.

Published Apr 20, 2021 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2021-25299: Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS).

Nagios XI version xi-5.7.5 is affected by cross-site scripting (XSS). The vulnerability exists in the file /usr/local/nagiosxi/html/admin/sshterm.php due to improper sanitization of user-controlled input. A maliciously crafted URL, when clicked by an admin user, can be used to steal his/her session cookies or it can be chained with the previous bugs to get one-click remote command execution (RCE) on the Nagios XI server.

Published Feb 15, 2021 · Updated Jul 9, 2026

High · CVSS 8.8 · CISA KEV

CVE-2021-25298: Nagios XI version xi-5.7.5 is affected by OS command injection.

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Published Feb 15, 2021 · Updated Jul 9, 2026

High · CVSS 8.8 · CISA KEV

CVE-2021-25297: Nagios XI version xi-5.7.5 is affected by OS command injection.

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Published Feb 15, 2021 · Updated Jul 9, 2026

High · CVSS 8.8 · CISA KEV

CVE-2021-25296: Nagios XI version xi-5.7.5 is affected by OS command injection.

Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlled input by a single HTTP request, which can lead to OS command injection on the Nagios XI server.

Published Feb 15, 2021 · Updated Jul 9, 2026

High · CVSS 7.7

CVE-2021-47987: Parse Server - Arbitrary Code Execution via Malicious Version Tags

Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to an unreviewed personal fork of a contributor with write access. No releases were published with these tags; a project was exposed only if it defined a git-based dependency referencing one of the affected tags (for example, parse-server#4.9.3). The code behind the tags was not reviewed or approved, and although no malicious code was identified, the introduction of security vulnerabilities could not be ruled out.

Published Jun 25, 2026 · Updated Jun 26, 2026

High · CVSS 7.7

CVE-2021-47986: Parse Server - Unreviewed Code Execution via Malicious Version Tags

Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed code in a personal fork. Attackers could exploit this by specifying affected version tags in dependency declarations to execute unreviewed and potentially malicious code.

Published Jun 25, 2026 · Updated Jun 26, 2026