2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-43811 | HIGH | 7.8 | 2.4% | Dec 8, 2021 | Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses Y... |
| CVE-2021-43539 | HIGH | 8.8 | 1.6% | Dec 8, 2021 | Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within t... |
| CVE-2021-43537 | HIGH | 8.8 | 2.0% | Dec 8, 2021 | An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a po... |
| CVE-2021-43535 | HIGH | 8.8 | 1.1% | Dec 8, 2021 | A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory c... |
| CVE-2021-43534 | HIGH | 8.8 | 1.2% | Dec 8, 2021 | Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2. Some of... |
| CVE-2021-38510 | HIGH | 8.8 | 1.0% | Dec 8, 2021 | The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run c... |
| CVE-2021-38504 | HIGH | 8.8 | 1.6% | Dec 8, 2021 | When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have r... |
| CVE-2021-37941 | HIGH | 7.8 | 0.2% | Dec 8, 2021 | A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a maliciou... |
| CVE-2021-23862 | HIGH | 7.2 | 1.4% | Dec 8, 2021 | A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in... |
| CVE-2021-23859 | HIGH | 7.5 | 1.0% | Dec 8, 2021 | An unauthenticated attacker is able to send a special HTTP request, that causes a service to crash. In case of a standal... |
| CVE-2021-21957 | HIGH | 7.3 | 1.2% | Dec 8, 2021 | A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report ODS Remote Connector 20.2... |
| CVE-2021-36719 | HIGH | 8.8 | 1.1% | Dec 8, 2021 | PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The attacker exploits the vulner... |
| CVE-2021-43978 | HIGH | 8.1 | 0.7% | Dec 8, 2021 | Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users... |
| CVE-2021-43809 | HIGH | 7.3 | 2.8% | Dec 8, 2021 | `Bundler` is a package for managing application dependencies in Ruby. In `bundler` versions before 2.2.33, when working ... |
| CVE-2021-43399 | HIGH | 7.5 | 1.4% | Dec 8, 2021 | The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the lengt... |
| CVE-2021-41017 | HIGH | 8.8 | 1.9% | Dec 8, 2021 | Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 thro... |
| CVE-2021-36195 | HIGH | 8.8 | 1.1% | Dec 8, 2021 | Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 thro... |
| CVE-2021-36173 | HIGH | 8.8 | 1.4% | Dec 8, 2021 | A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 thr... |
| CVE-2021-41090 | HIGH | 7.5 | 0.7% | Dec 8, 2021 | Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observabilit... |
| CVE-2021-27860 | HIGH | 8.8 | 39.8% | Dec 8, 2021 | A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p9... |
| CVE-2021-42110 | HIGH | 7.8 | 0.3% | Dec 8, 2021 | An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate priv... |
| CVE-2021-41450 | HIGH | 7.5 | 2.3% | Dec 8, 2021 | An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the ... |
| CVE-2021-42835 | HIGH | 7 | 1.2% | Dec 8, 2021 | An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint v... |
| CVE-2021-40861 | HIGH | 7.2 | 1.7% | Dec 8, 2021 | A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) 9.0.017.07 allow... |
| CVE-2021-40860 | HIGH | 7.2 | 1.7% | Dec 8, 2021 | A SQL Injection in the custom filter query component in Genesys intelligent Workload Distribution (IWD) before 9.0.013.1... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now