2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34569CRITICAL9.8In WAGO I/O-Check Service in multiple products an attacker can send a specially crafted packet containing OS commands to...
CVE-2021-34568HIGH7.5In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co...
CVE-2021-34567HIGH8.2In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co...
CVE-2021-34566CRITICAL9.1In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co...
CVE-2021-39661HIGH7.8In _PMRLogicalOffsetToPhysicalOffset of the PowerVR kernel driver, there is a possible out of bounds write due to a miss...
CVE-2021-1050HIGH7.8In MMU_UnmapPages of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. T...
CVE-2021-40303MEDIUM5.4perfex crm 1.10 is vulnerable to Cross Site Scripting (XSS) via /clients/profile.
CVE-2021-42205MEDIUM4.7ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows loca...
CVE-2021-39473MEDIUM5.4Saibamen HotelManager v1.2 is vulnerable to Cross Site Scripting (XSS) due to improper sanitization of comment and conta...
CVE-2021-39432MEDIUM6.5diplib v3.0.0 is vulnerable to Double Free.
CVE-2021-34055HIGH7.8jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
CVE-2021-41576Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves...
CVE-2021-41575Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves...
CVE-2021-41574Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves...
CVE-2021-34686Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further inves...
CVE-2021-44862HIGH7.8Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information sto...
CVE-2021-39077MEDIUM4.4IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, 11.3, and 11.4 stores user credentials in plain clear text which can...
CVE-2021-36906HIGH8.8Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 ...
CVE-2021-37823MEDIUM4.9OpenCart 3.0.3.7 allows users to obtain database information or read server files through SQL injection in the backgroun...
CVE-2021-46853MEDIUM5.9Alpine before 2.25 allows remote attackers to cause a denial of service (application crash) when LIST or LSUB is sent be...
CVE-2021-45448MEDIUM6.5Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 using the Pentaho Analyzer plugin exposes a ser...
CVE-2021-45447HIGH7.5 Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage ...
CVE-2021-45446HIGH7.5A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not ca...
CVE-2021-37789HIGH8.1stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service...
CVE-2021-27784HIGH7.5The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix pr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now