2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-45470HIGH7.5lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular ex...
CVE-2021-3621HIGH8.8A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cach...
CVE-2021-44542HIGH7.5A memory leak vulnerability was found in Privoxy when handling errors.
CVE-2021-44541HIGH7.5A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory whe...
CVE-2021-44540HIGH7.5A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec ...
CVE-2021-43989HIGH7.5mySCADA myPRO Versions 8.20.0 and prior stores passwords using MD5, which may allow an attacker to crack the previously ...
CVE-2021-3584HIGH7.2A server side remote code execution vulnerability was found in Foreman project. A authenticated attacker could use Sendm...
CVE-2021-35243HIGH7.5The HTTP PUT and DELETE methods were enabled in the Web Help Desk web server (12.7.7 and earlier), allowing users to exe...
CVE-2021-20318HIGH7.2The HornetQ component of Artemis in EAP 7 was not updated with the fix for CVE-2016-4978. A remote attacker could use th...
CVE-2021-45469HIGH7.8In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when ...
CVE-2021-40161HIGH7.8A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earli...
CVE-2021-40160HIGH7.8PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF ...
CVE-2021-4118HIGH7.8pytorch-lightning is vulnerable to Deserialization of Untrusted Data
CVE-2021-43854HIGH7.5NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2021-23175HIGH8.2NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply indi...
CVE-2021-44600HIGH7.5The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injectio...
CVE-2021-44599HIGH7.5The id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. ...
CVE-2021-44273HIGH7.4e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mod...
CVE-2021-4144HIGH8.8TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.
CVE-2021-45463HIGH7.8load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or ...
CVE-2021-45462HIGH7.5In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
CVE-2021-20050HIGH7.5An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessi...
CVE-2021-20049HIGH7.5A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 usern...
CVE-2021-4079HIGH8.8Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit he...
CVE-2021-4078HIGH8.8Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corrup...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now