2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25832 | CRITICAL | 9.8 | 12.6% | Mar 1, 2021 | A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentSer... |
| CVE-2021-25831 | CRITICAL | 9.8 | 11.5% | Mar 1, 2021 | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker mus... |
| CVE-2021-25830 | CRITICAL | 9.8 | 11.8% | Mar 1, 2021 | A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacke... |
| CVE-2021-27132 | CRITICAL | 9.8 | 16.7% | Feb 27, 2021 | SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via... |
| CVE-2021-3197 | CRITICAL | 9.8 | 72.3% | Feb 27, 2021 | An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by... |
| CVE-2021-3148 | CRITICAL | 9.8 | 8.2% | Feb 27, 2021 | An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt... |
| CVE-2021-3144 | CRITICAL | 9.1 | 5.2% | Feb 27, 2021 | In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command agai... |
| CVE-2021-25283 | CRITICAL | 9.8 | 10.4% | Feb 27, 2021 | An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side... |
| CVE-2021-25282 | CRITICAL | 9.1 | 92.3% | Feb 27, 2021 | An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable ... |
| CVE-2021-25281 | CRITICAL | 9.8 | 72.9% | Feb 27, 2021 | An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel... |
| CVE-2021-27198 | CRITICAL | 9.8 | 13.6% | Feb 26, 2021 | An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur... |
| CVE-2021-26566 | CRITICAL | 9 | 1.4% | Feb 26, 2021 | Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) befo... |
| CVE-2021-21308 | CRITICAL | 9.1 | 1.0% | Feb 26, 2021 | PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout syste... |
| CVE-2021-26904 | CRITICAL | 9.8 | 2.0% | Feb 26, 2021 | LMA ISIDA Retriever 5.2 allows SQL Injection. |
| CVE-2021-24094 | CRITICAL | 9.8 | 22.1% | Feb 25, 2021 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2021-24078 | CRITICAL | 9.8 | 11.2% | Feb 25, 2021 | Windows DNS Server Remote Code Execution Vulnerability |
| CVE-2021-24077 | CRITICAL | 9.8 | 2.7% | Feb 25, 2021 | Windows Fax Service Remote Code Execution Vulnerability |
| CVE-2021-24074 | CRITICAL | 9.8 | 25.7% | Feb 25, 2021 | Windows TCP/IP Remote Code Execution Vulnerability |
| CVE-2021-3406 | CRITICAL | 9.8 | 0.7% | Feb 25, 2021 | A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptogra... |
| CVE-2021-27670 | CRITICAL | 9.8 | 61.3% | Feb 25, 2021 | Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter. |
| CVE-2021-1393 | CRITICAL | 9.8 | 2.3% | Feb 24, 2021 | Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain pr... |
| CVE-2021-1388 | CRITICAL | 10 | 14.4% | Feb 24, 2021 | A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engi... |
| CVE-2021-1361 | CRITICAL | 9.1 | 1.6% | Feb 24, 2021 | A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Ci... |
| CVE-2021-22667 | CRITICAL | 9.8 | 3.6% | Feb 24, 2021 | BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an... |
| CVE-2021-21972 | CRITICAL | 9.8 | 99.5% | Feb 24, 2021 | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now