2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-25916CRITICAL9.8Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of s...
CVE-2021-26987CRITICAL9.8Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are s...
CVE-2021-27817CRITICAL9.8A remote command execution vulnerability in shopxo 1.9.3 allows an attacker to upload malicious code generated by phar w...
CVE-2021-23356CRITICAL9.8This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible ...
CVE-2021-23355CRITICAL9.8This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is p...
CVE-2021-20232CRITICAL9.8A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory ...
CVE-2021-20231CRITICAL9.8A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption a...
CVE-2021-28308CRITICAL9.1An issue was discovered in the fltk crate before 0.15.3 for Rust. There is an out-of bounds read because the pixmap cons...
CVE-2021-28305CRITICAL9.8An issue was discovered in the diesel crate before 1.4.6 for Rust. There is a use-after-free in the SQLite backend becau...
CVE-2021-27647CRITICAL9.8Out-of-bounds Read vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 ...
CVE-2021-27646CRITICAL9.8Use After Free vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6.2.3-25426-3 allo...
CVE-2021-28154CRITICAL9.1Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted I...
CVE-2021-22714CRITICAL9.8A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION...
CVE-2021-28141CRITICAL9.8An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAj...
CVE-2021-27080CRITICAL9.3Azure Sphere Unsigned Code Execution Vulnerability
CVE-2021-26897CRITICAL9.8Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26895CRITICAL9.8Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26894CRITICAL9.8Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26893CRITICAL9.8Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26877CRITICAL9.8Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-26867CRITICAL9.9Windows Hyper-V Remote Code Execution Vulnerability
CVE-2021-28132CRITICAL9.8LUCY Security Awareness Software through 4.7.x allows unauthenticated remote code execution because the Migration Tool (...
CVE-2021-28134CRITICAL9.8Clipper before 1.0.5 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vu...
CVE-2021-24030CRITICAL9.8The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the exe...
CVE-2021-24025CRITICAL9.8Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function ca...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now