2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-4069HIGH7.8vim is vulnerable to Use After Free
CVE-2021-43469HIGH8.8VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.
CVE-2021-43041HIGH8.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format...
CVE-2021-43040HIGH8.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leverage...
CVE-2021-43038HIGH8.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by...
CVE-2021-43037HIGH7.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable t...
CVE-2021-43034HIGH7.8An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to...
CVE-2021-44048HIGH7.8An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer b...
CVE-2021-44047HIGH7.8A use-after-free vulnerability exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.1...
CVE-2021-44046HIGH7.8An out-of-bounds write vulnerability exists when reading U3D files in Open Design Alliance PRC SDK before 2022.11. An un...
CVE-2021-44045HIGH7.8An out-of-bounds write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022....
CVE-2021-44044HIGH7.8An out-of-bounds write vulnerability exists when reading a JPG file using Open Design Alliance Drawings SDK before 2022....
CVE-2021-37253HIGH7.5M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range o...
CVE-2021-43415HIGH8.8HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenti...
CVE-2021-35413HIGH8.8A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated a...
CVE-2021-23562HIGH8.8This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An att...
CVE-2021-29756HIGH8.8IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which cou...
CVE-2021-20470HIGH7.5IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes ...
CVE-2021-3980HIGH7.5elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor
CVE-2021-44021HIGH7.8An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker...
CVE-2021-44020HIGH7.8An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker...
CVE-2021-44019HIGH7.8An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker...
CVE-2021-25784HIGH7.2Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article.
CVE-2021-25783HIGH7.2Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search.
CVE-2021-28236HIGH7.5LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now