2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0397 | CRITICAL | 9.8 | 5.7% | Mar 10, 2021 | In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to... |
| CVE-2021-0396 | CRITICAL | 9.8 | 1.9% | Mar 10, 2021 | In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds... |
| CVE-2021-28122 | CRITICAL | 9.8 | 4.0% | Mar 10, 2021 | A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an una... |
| CVE-2021-28119 | CRITICAL | 9.8 | 3.6% | Mar 9, 2021 | Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC... |
| CVE-2021-23352 | CRITICAL | 9.8 | 2.1% | Mar 9, 2021 | This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath optio... |
| CVE-2021-25915 | CRITICAL | 9.8 | 3.5% | Mar 9, 2021 | Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of se... |
| CVE-2021-21484 | CRITICAL | 9.8 | 1.2% | Mar 9, 2021 | LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured... |
| CVE-2021-21335 | CRITICAL | 9.8 | 1.7% | Mar 8, 2021 | In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentica... |
| CVE-2021-21329 | CRITICAL | 9.8 | 1.5% | Mar 8, 2021 | RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF user... |
| CVE-2021-27581 | CRITICAL | 9.8 | 1.6% | Mar 5, 2021 | The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter. |
| CVE-2021-3420 | CRITICAL | 9.8 | 2.1% | Mar 5, 2021 | A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions m... |
| CVE-2021-26705 | CRITICAL | 9.1 | 2.1% | Mar 5, 2021 | An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getC... |
| CVE-2021-28037 | CRITICAL | 9.8 | 1.2% | Mar 5, 2021 | An issue was discovered in the internment crate before 0.4.2 for Rust. There is a data race that can cause memory corrup... |
| CVE-2021-28035 | CRITICAL | 9.8 | 1.2% | Mar 5, 2021 | An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a drop of unin... |
| CVE-2021-28034 | CRITICAL | 9.8 | 1.2% | Mar 5, 2021 | An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a double free ... |
| CVE-2021-28033 | CRITICAL | 9.8 | 1.2% | Mar 5, 2021 | An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a... |
| CVE-2021-28032 | CRITICAL | 9.8 | 1.4% | Mar 5, 2021 | An issue was discovered in the nano_arena crate before 0.5.2 for Rust. There is an aliasing violation in split_at becaus... |
| CVE-2021-28031 | CRITICAL | 9.8 | 1.4% | Mar 5, 2021 | An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free... |
| CVE-2021-28028 | CRITICAL | 9.8 | 1.2% | Mar 5, 2021 | An issue was discovered in the toodee crate before 0.3.0 for Rust. Row insertion can cause a double free upon an iterato... |
| CVE-2021-28027 | CRITICAL | 9.8 | 1.2% | Mar 5, 2021 | An issue was discovered in the bam crate before 0.1.3 for Rust. There is an integer underflow and out-of-bounds write du... |
| CVE-2021-27965 | CRITICAL | 9.8 | 11.8% | Mar 5, 2021 | The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privileg... |
| CVE-2021-27964 | CRITICAL | 9.8 | 46.0% | Mar 5, 2021 | SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con... |
| CVE-2021-27314 | CRITICAL | 9.8 | 12.4% | Mar 5, 2021 | SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL q... |
| CVE-2021-25346 | CRITICAL | 9.8 | 1.2% | Mar 4, 2021 | A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arb... |
| CVE-2021-26293 | CRITICAL | 9.8 | 7.1% | Mar 4, 2021 | An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now