2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-46840CRITICAL9.1The HW_KEYMASTER module has an out-of-bounds access vulnerability in parameter set verification.Successful exploitation ...
CVE-2021-46839CRITICAL9.1The HW_KEYMASTER module has a vulnerability of missing bounds check on length.Successful exploitation of this vulnerabil...
CVE-2021-45790CRITICAL9.8An arbitrary file upload vulnerability was found in Metersphere v1.15.4. Unauthenticated users can upload any file to ar...
CVE-2021-41433CRITICAL9.8SQL Injection vulnerability exists in version 1.0 of the Resumes Management and Job Application Website application logi...
CVE-2021-43310CRITICAL9.8A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys ...
CVE-2021-40019CRITICAL9.1Out-of-bounds heap read vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may caus...
CVE-2021-40017CRITICAL9.8The HW_KEYMASTER module lacks the validity check of the key format. Successful exploitation of this vulnerability may re...
CVE-2021-42949CRITICAL9.8The component controlla_login function in HotelDruid Hotel Management Software v3.0.3 generates a predictable session to...
CVE-2021-0942CRITICAL9.8The path in this case is a little bit convoluted. The end result is that via an ioctl an untrusted app can control the u...
CVE-2021-44835CRITICAL9.8An issue was discovered in Active Intelligent Visualization 5. The Vdc header is used in a SQL query without being sanit...
CVE-2021-34236CRITICAL9.8Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cau...
CVE-2021-36783CRITICAL9.9A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Member...
CVE-2021-36782CRITICAL9.9A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster ...
CVE-2021-27693CRITICAL9.8Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the ...
CVE-2021-43329CRITICAL9.8A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attac...
CVE-2021-39815CRITICAL9.8The PowerVR GPU driver allows unprivileged apps to allocated pinned memory, unpin it (which makes it available to be fre...
CVE-2021-42627CRITICAL9.8The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without auth...
CVE-2021-42232CRITICAL9.8TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnera...
CVE-2021-3586CRITICAL9.8A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify whic...
CVE-2021-39085CRITICAL9.8IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1...
CVE-2021-22289CRITICAL9.8Improper Input Validation vulnerability in the project upload mechanism in B&R Automation Studio version >=4.0 may allow...
CVE-2021-33643CRITICAL9.1An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo...
CVE-2021-41615CRITICAL9.8websda.c in GoAhead WebServer 2.1.8 has insufficient nonce entropy because the nonce calculation relies on the hardcoded...
CVE-2021-41556CRITICAL10sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that ca...
CVE-2021-22650CRITICAL9.8An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWin...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now