2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-46840CRITICAL9.1The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation ...
CVE-2021-46839CRITICAL9.1The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerabil...
CVE-2021-20030HIGH7.5SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web ...
CVE-2021-36369HIGH7.5An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication me...
CVE-2021-36201MEDIUM5.3Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versi...
CVE-2021-36915MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in Cozmoslabs Profile Builder plugin <= 3.6.0 at WordPress allows upload...
CVE-2021-0951HIGH7.8In DevmemIntHeapAcquire of TBD, there is a possible arbitrary code execution due to an integer overflow. This could lead...
CVE-2021-0696HIGH7In dllist_remove_node of TBD, there is a possible use after free bug due to a race condition. This could lead to local e...
CVE-2021-36913HIGH7.5Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= ...
CVE-2021-36899MEDIUM4.8Authenticated (admin+) Reflected Cross-Site Scripting (XSS) vulnerability in Gabe Livan's Asset CleanUp: Page Speed Boos...
CVE-2021-35226MEDIUM6.5An entity in Network Configuration Manager product is misconfigured and exposing password field to Solarwinds Informatio...
CVE-2021-25044MEDIUM6.1The Cryptocurrency Pricing list and Ticker WordPress plugin through 1.5 does not sanitise and escape the ccpw_setpage pa...
CVE-2021-44171HIGH8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version...
CVE-2021-40166HIGH7.8A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has ...
CVE-2021-40165HIGH7.8A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond th...
CVE-2021-40164HIGH7.8A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploite...
CVE-2021-40163HIGH7.8A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Imag...
CVE-2021-40162HIGH7.8A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond a...
CVE-2021-40556HIGH8.8A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulne...
CVE-2021-36865MEDIUM4.3Insecure direct object references (IDOR) vulnerability in ExpressTech Quiz And Survey Master plugin <= 7.3.4 at WordPres...
CVE-2021-33354HIGH8.1Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via ...
CVE-2021-36855MEDIUM6.1Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at W...
CVE-2021-36854HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
CVE-2021-36839MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Social Media Follow Buttons Bar plugin <= 4.73...
CVE-2021-36830MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Comment Guestbook plugin <= 0.8.0 at WordPress...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now