2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31566HIGH7.8An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control ...
CVE-2021-23177HIGH7.8An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the t...
CVE-2021-23161Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-23156Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-20316MEDIUM6.8A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permi...
CVE-2021-20304HIGH7.5A flaw was found in OpenEXR's hufDecode functionality. This flaw allows an attacker who can pass a crafted file to be pr...
CVE-2021-20298HIGH7.5A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed ...
CVE-2021-42627CRITICAL9.8The WAN configuration page "wan.htm" on D-Link DIR-615 devices with firmware 20.06 can be accessed directly without auth...
CVE-2021-42232CRITICAL9.8TP-Link Archer A7 Archer A7(US)_V5_210519 is affected by a command injection vulnerability in /usr/bin/tddp. The vulnera...
CVE-2021-28861HIGH7.4Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multipl...
CVE-2021-29891MEDIUM4.9IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause...
CVE-2021-3484Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-3408Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-3659MEDIUM5.5A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way t...
CVE-2021-3639MEDIUM6.1A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an atta...
CVE-2021-3590HIGH8.8A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password t...
CVE-2021-3586CRITICAL9.8A flaw was found in servicemesh-operator. The NetworkPolicy resources installed for Maistra do not properly specify whic...
CVE-2021-3521MEDIUM4.7There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signa...
CVE-2021-3513HIGH7.5A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. ...
CVE-2021-3481HIGH7.1A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/...
CVE-2021-3442MEDIUM5.4A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated ...
CVE-2021-37289HIGH7.2Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system c...
CVE-2021-36857MEDIUM5.4Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in wpshopmart Testimonial Builder plugin <= 1.6....
CVE-2021-36852HIGH8Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.
CVE-2021-36847MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebbaPlugins Webba Booking plugin <= 4.2.21 at...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now