2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0871HIGH7.8In PVRSRVBridgePMRPDumpSymbolicAddr of the PowerVR kernel driver, a missing size check means there is a possible integer...
CVE-2021-0697HIGH7In PVRSRVRGXSubmitTransferKM of rgxtransfer.c, there is a possible user after free due to a race condition. This could l...
CVE-2021-44426HIGH8.8An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's loc...
CVE-2021-44425MEDIUM6.5An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machin...
CVE-2021-37819HIGH7.5PDF Labs pdftk-java v3.2.3 was discovered to contain an infinite loop via the component /text/pdf/PdfReader.java.
CVE-2021-44835CRITICAL9.8An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanit...
CVE-2021-40648MEDIUM5.5In man2html 1.6g, a filename can be created to overwrite the previous size parameter of the next chunk and the fd, bk, f...
CVE-2021-40647MEDIUM5.5In man2html 1.6g, a specific string being read in from a file will overwrite the size parameter in the top chunk of the ...
CVE-2021-34236CRITICAL9.8Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cau...
CVE-2021-36783CRITICAL9.9A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Member...
CVE-2021-36782CRITICAL9.9A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster ...
CVE-2021-43565HIGH7.5The x/crypto/ssh package before 0.0.0-20211202192323-5770296d904e of golang.org/x/crypto allows an attacker to panic an ...
CVE-2021-39326Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-39324Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-36829MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop Launcher: Coming Soon & Maintenanc...
CVE-2021-43080MEDIUM5.4An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version ...
CVE-2021-43076MEDIUM6.5An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 an...
CVE-2021-28398HIGH7.2A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to ...
CVE-2021-27693CRITICAL9.8Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the ...
CVE-2021-44718MEDIUM5.9wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sendi...
CVE-2021-35135MEDIUM5.5A null pointer dereference may potentially occur during RSA key import in Snapdragon Auto, Snapdragon Compute, Snapdrago...
CVE-2021-35134HIGH8.4Due to insufficient validation of ELF headers, an Incorrect Calculation of Buffer Size can occur in Boot leading to memo...
CVE-2021-35133MEDIUM6.7Use after free in the synx driver issue while performing other functions during multiple invocation of synx release call...
CVE-2021-35132HIGH7.8Out of bound write in DSP service due to improper bound check for response buffer size in Snapdragon Auto, Snapdragon Co...
CVE-2021-35122HIGH7.8Non-secure region can try modifying RG permissions of IO space xPUs due to improper input validation in Snapdragon Auto,...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now