2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-25832CRITICAL9.8A heap buffer overflow vulnerability inside of BMP image processing was found at [core] module of ONLYOFFICE DocumentSer...
CVE-2021-25831CRITICAL9.8A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.3. An attacker mus...
CVE-2021-25830CRITICAL9.8A file extension handling issue was found in [core] module of ONLYOFFICE DocumentServer v4.2.0.236-v5.6.4.13. An attacke...
CVE-2021-27132CRITICAL9.8SerComm AG Combo VD625 AGSOT_2.1.0 devices allow CRLF injection (for HTTP header injection) in the download function via...
CVE-2021-3197CRITICAL9.8An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by...
CVE-2021-3148CRITICAL9.8An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt...
CVE-2021-3144CRITICAL9.1In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command agai...
CVE-2021-25283CRITICAL9.8An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side...
CVE-2021-25282CRITICAL9.1An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable ...
CVE-2021-25281CRITICAL9.8An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel...
CVE-2021-27198CRITICAL9.8An issue was discovered in Visualware MyConnection Server before v11.1a. Unauthenticated Remote Code Execution can occur...
CVE-2021-26566CRITICAL9Insertion of sensitive information into sent data vulnerability in synorelayd in Synology DiskStation Manager (DSM) befo...
CVE-2021-21308CRITICAL9.1PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 the soft logout syste...
CVE-2021-26904CRITICAL9.8LMA ISIDA Retriever 5.2 allows SQL Injection.
CVE-2021-24094CRITICAL9.8Windows TCP/IP Remote Code Execution Vulnerability
CVE-2021-24078CRITICAL9.8Windows DNS Server Remote Code Execution Vulnerability
CVE-2021-24077CRITICAL9.8Windows Fax Service Remote Code Execution Vulnerability
CVE-2021-24074CRITICAL9.8Windows TCP/IP Remote Code Execution Vulnerability
CVE-2021-3406CRITICAL9.8A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptogra...
CVE-2021-27670CRITICAL9.8Appspace 6.2.4 allows SSRF via the api/v1/core/proxy/jsonprequest url parameter.
CVE-2021-1393CRITICAL9.8Multiple vulnerabilities in Cisco Application Services Engine could allow an unauthenticated, remote attacker to gain pr...
CVE-2021-1388CRITICAL10A vulnerability in an API endpoint of Cisco ACI Multi-Site Orchestrator (MSO) installed on the Application Services Engi...
CVE-2021-1361CRITICAL9.1A vulnerability in the implementation of an internal file management service for Cisco Nexus 3000 Series Switches and Ci...
CVE-2021-22667CRITICAL9.8BB-ESWGP506-2SFP-T versions 1.01.09 and prior is vulnerable due to the use of hard-coded credentials, which may allow an...
CVE-2021-21972CRITICAL9.8The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now