2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-43851HIGH8.8Anuko Time Tracker is an open source, web-based time tracking application written in PHP. SQL injection vulnerability ex...
CVE-2021-44860HIGH7.8An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.1...
CVE-2021-44859HIGH7.8An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.1...
CVE-2021-44423HIGH7.8An out-of-bounds read vulnerability exists when reading a BMP file using Open Design Alliance (ODA) Drawings Explorer be...
CVE-2021-44422HIGH7.8An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before...
CVE-2021-45290HIGH7.5A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.
CVE-2021-44207HIGH8.1Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
CVE-2021-27449HIGH8.8Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute comman...
CVE-2021-27445HIGH7.8Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges ...
CVE-2021-44877HIGH7.5Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP s...
CVE-2021-44874HIGH8.8Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam ap...
CVE-2021-43839HIGH7.5Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to...
CVE-2021-36350HIGH7.5Dell PowerScale OneFS, versions 8.2.2-9.3.0.x, contain an authentication bypass by primary weakness in one of the authen...
CVE-2021-36337HIGH7.4Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 whi...
CVE-2021-36316HIGH7.2Dell EMC Avamar Server versions 18.2, 19.1, 19.2, 19.3, and 19.4 contain an improper privilege management vulnerability ...
CVE-2021-24981HIGH7.5The Directorist WordPress plugin before 7.0.6.2 was vulnerable to Cross-Site Request Forgery to Remote File Upload leadi...
CVE-2021-24846HIGH8.8The get_query() function of the Ni WooCommerce Custom Order Status WordPress plugin before 1.9.7, used by the niwoocos_a...
CVE-2021-24750HIGH8.8The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refU...
CVE-2021-24739HIGH8.1The Logo Carousel WordPress plugin before 3.4.2 allows users with a role as low as Contributor to duplicate and view arb...
CVE-2021-45451HIGH7.5In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer...
CVE-2021-45450HIGH7.5In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or ora...
CVE-2021-43844HIGH8.8MSEdgeRedirect is a tool to redirect news, search, widgets, weather, and more to a user's default browser. MSEdgeRedirec...
CVE-2021-43843HIGH7.5jsx-slack is a package for building JSON objects for Slack block kit surfaces from JSX. The maintainers found the patch ...
CVE-2021-3860HIGH8.8JFrog Artifactory before 7.25.4 (Enterprise+ deployments only), is vulnerable to Blind SQL Injection by a low privileged...
CVE-2021-44181HIGH7.8Adobe Dimension versions 3.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now