2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34986HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (...
CVE-2021-36461HIGH8.8An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upl...
CVE-2021-4135MEDIUM5.5A memory leak vulnerability was found in the Linux kernel's eBPF for the Simulated networking device driver in the way u...
CVE-2021-26384HIGH7.8A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info da...
CVE-2021-26382MEDIUM4.4An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (AC...
CVE-2021-39028MEDIUM5.4IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header i...
CVE-2021-39019MEDIUM6.5IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitiv...
CVE-2021-39018MEDIUM4.3IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive infor...
CVE-2021-39017MEDIUM6.5IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker ...
CVE-2021-39016MEDIUM4.3IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 does not sufficiently monitor ...
CVE-2021-39015MEDIUM5.4IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vu...
CVE-2021-45492HIGH7.8In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be th...
CVE-2021-27294Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-46827MEDIUM6.1An issue was discovered in Oxygen XML WebHelp before 22.1 build 2021082006 and 23.x before 23.1 build 2021090310. An XSS...
CVE-2021-39041MEDIUM5.3IBM QRadar SIEM 7.3, 7.4, and 7.5 may be vulnerable to partial denial of service attack, resulting in some protocols not...
CVE-2021-46741HIGH7.5The basic framework and setting module have defects, which were introduced during the design. Successful exploitation of...
CVE-2021-41396HIGH7.5Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a shor...
CVE-2021-40016MEDIUM6.5Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will aff...
CVE-2021-40013MEDIUM6.5Improper permission control vulnerability in the Bluetooth module.Successful exploitation of this vulnerability will aff...
CVE-2021-40012HIGH7.5Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitatio...
CVE-2021-39999HIGH7.5There is a buffer overflow vulnerability in eSE620X vESS V100R001C10SPC200 and V100R001C20SPC200. An attacker can exploi...
CVE-2021-38289HIGH8.8An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allow...
CVE-2021-36668HIGH7.8URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parame...
CVE-2021-36667HIGH7.8Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via craf...
CVE-2021-36666HIGH7.8An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDeco...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now