2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-0397CRITICAL9.8In sdp_copy_raw_data of sdp_discovery.cc, there is a possible system compromise due to a double free. This could lead to...
CVE-2021-0396CRITICAL9.8In Builtins::Generate_ArgumentsAdaptorTrampoline of builtins-arm.cc and related files, there is a possible out of bounds...
CVE-2021-28122CRITICAL9.8A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an una...
CVE-2021-28119CRITICAL9.8Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC...
CVE-2021-23352CRITICAL9.8This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath optio...
CVE-2021-25915CRITICAL9.8Prototype pollution vulnerability in 'changeset' versions 0.0.1 through 0.2.5 allows an attacker to cause a denial of se...
CVE-2021-21484CRITICAL9.8LDAP authentication in SAP HANA Database version 2.0 can be bypassed if the attached LDAP directory server is configured...
CVE-2021-21335CRITICAL9.8In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentica...
CVE-2021-21329CRITICAL9.8RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF user...
CVE-2021-27581CRITICAL9.8The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
CVE-2021-3420CRITICAL9.8A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions m...
CVE-2021-26705CRITICAL9.1An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getC...
CVE-2021-28037CRITICAL9.8An issue was discovered in the internment crate before 0.4.2 for Rust. There is a data race that can cause memory corrup...
CVE-2021-28035CRITICAL9.8An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a drop of unin...
CVE-2021-28034CRITICAL9.8An issue was discovered in the stack_dst crate before 0.6.1 for Rust. Because of the push_inner behavior, a double free ...
CVE-2021-28033CRITICAL9.8An issue was discovered in the byte_struct crate before 0.6.1 for Rust. There can be a drop of uninitialized memory if a...
CVE-2021-28032CRITICAL9.8An issue was discovered in the nano_arena crate before 0.5.2 for Rust. There is an aliasing violation in split_at becaus...
CVE-2021-28031CRITICAL9.8An issue was discovered in the scratchpad crate before 1.3.1 for Rust. The move_elements function can have a double-free...
CVE-2021-28028CRITICAL9.8An issue was discovered in the toodee crate before 0.3.0 for Rust. Row insertion can cause a double free upon an iterato...
CVE-2021-28027CRITICAL9.8An issue was discovered in the bam crate before 0.1.3 for Rust. There is an integer underflow and out-of-bounds write du...
CVE-2021-27965CRITICAL9.8The MsIo64.sys driver before 1.1.19.1016 in MSI Dragon Center before 2.0.98.0 has a buffer overflow that allows privileg...
CVE-2021-27964CRITICAL9.8SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con...
CVE-2021-27314CRITICAL9.8SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL q...
CVE-2021-25346CRITICAL9.8A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arb...
CVE-2021-26293CRITICAL9.8An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now