2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-30454CRITICAL9.8An issue was discovered in the outer_cgi crate before 0.2.1 for Rust. A user-provided Read instance receives an uninitia...
CVE-2021-30246CRITICAL9.1In the jsrsasign package through 10.1.13 for Node.js, some invalid RSA PKCS#1 v1.5 signatures are mistakenly recognized ...
CVE-2021-21425CRITICAL9.8Grav Admin Plugin is an HTML user interface that provides a way to configure Grav and create and modify pages. In versio...
CVE-2021-30177CRITICAL9.8There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execut...
CVE-2021-26709CRITICAL9.8D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated...
CVE-2021-24026CRITICAL9.8A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, W...
CVE-2021-30045CRITICAL9.1SerenityOS 2021-03-27 contains a buffer overflow vulnerability in the EndOfCentralDirectory::read() function.
CVE-2021-27698CRITICAL9.8RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c throug...
CVE-2021-27697CRITICAL9.8RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the g...
CVE-2021-27357CRITICAL9.8RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c.
CVE-2021-28173CRITICAL9.8The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers c...
CVE-2021-28171CRITICAL9.8The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions...
CVE-2021-30164CRITICAL9.8Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by lev...
CVE-2021-30149CRITICAL9.8Composr 10.0.36 allows upload and execution of PHP files.
CVE-2021-20308CRITICAL9.8Integer overflow in the htmldoc 1.9.11 and before may allow attackers to execute arbitrary code and cause a denial of se...
CVE-2021-20307CRITICAL9.8Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read a...
CVE-2021-24212CRITICAL9.8The WooCommerce Help Scout WordPress plugin before 2.9.1 (https://woocommerce.com/products/woocommerce-help-scout/) allo...
CVE-2021-24175CRITICAL9.8The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.7 was being actively exploited to by malicious ac...
CVE-2021-24171CRITICAL9.8The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions su...
CVE-2021-29996CRITICAL9.6Mark Text through 0.16.3 allows attackers arbitrary command execution. This could lead to Remote Code Execution (RCE) by...
CVE-2021-30072CRITICAL9.8An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based...
CVE-2021-28940CRITICAL9.8Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to...
CVE-2021-1871CRITICAL9.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-...
CVE-2021-1870CRITICAL9.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-...
CVE-2021-1818CRITICAL9.8A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now