2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4069 | HIGH | 7.8 | 1.3% | Dec 6, 2021 | vim is vulnerable to Use After Free |
| CVE-2021-43469 | HIGH | 8.8 | 2.3% | Dec 6, 2021 | VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component. |
| CVE-2021-43041 | HIGH | 8.8 | 2.3% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A crafted HTTP request could induce a format... |
| CVE-2021-43040 | HIGH | 8.8 | 1.8% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The privileged vaultServer could be leverage... |
| CVE-2021-43038 | HIGH | 8.8 | 2.2% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The wguest account could execute commands by... |
| CVE-2021-43037 | HIGH | 7.8 | 0.5% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Unitrends Windows agent was vulnerable t... |
| CVE-2021-43034 | HIGH | 7.8 | 0.4% | Dec 6, 2021 | An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. A world writable file allowed local users to... |
| CVE-2021-44048 | HIGH | 7.8 | 0.8% | Dec 5, 2021 | An out-of-bounds write vulnerability exists when reading a TIF file using Open Design Alliance (ODA) Drawings Explorer b... |
| CVE-2021-44047 | HIGH | 7.8 | 0.9% | Dec 5, 2021 | A use-after-free vulnerability exists when reading a DWF/DWFX file using Open Design Alliance Drawings SDK before 2022.1... |
| CVE-2021-44046 | HIGH | 7.8 | 0.8% | Dec 5, 2021 | An out-of-bounds write vulnerability exists when reading U3D files in Open Design Alliance PRC SDK before 2022.11. An un... |
| CVE-2021-44045 | HIGH | 7.8 | 0.8% | Dec 5, 2021 | An out-of-bounds write vulnerability exists when reading a DGN file using Open Design Alliance Drawings SDK before 2022.... |
| CVE-2021-44044 | HIGH | 7.8 | 0.8% | Dec 5, 2021 | An out-of-bounds write vulnerability exists when reading a JPG file using Open Design Alliance Drawings SDK before 2022.... |
| CVE-2021-37253 | HIGH | 7.5 | 2.8% | Dec 5, 2021 | M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range o... |
| CVE-2021-43415 | HIGH | 8.8 | 1.2% | Dec 3, 2021 | HashiCorp Nomad and Nomad Enterprise up to 1.0.13, 1.1.7, and 1.2.0, with the QEMU task driver enabled, allowed authenti... |
| CVE-2021-35413 | HIGH | 8.8 | 2.5% | Dec 3, 2021 | A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated a... |
| CVE-2021-23562 | HIGH | 8.8 | 1.0% | Dec 3, 2021 | This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An att... |
| CVE-2021-29756 | HIGH | 8.8 | 0.6% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to cross-site request forgery (CSRF) in the My Inbox page which cou... |
| CVE-2021-20470 | HIGH | 7.5 | 1.4% | Dec 3, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 does not require that users should have strong passwords by default, which makes ... |
| CVE-2021-3980 | HIGH | 7.5 | 1.6% | Dec 3, 2021 | elgg is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor |
| CVE-2021-44021 | HIGH | 7.8 | 0.3% | Dec 3, 2021 | An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker... |
| CVE-2021-44020 | HIGH | 7.8 | 0.3% | Dec 3, 2021 | An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker... |
| CVE-2021-44019 | HIGH | 7.8 | 0.3% | Dec 3, 2021 | An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker... |
| CVE-2021-25784 | HIGH | 7.2 | 1.1% | Dec 2, 2021 | Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Edit Article. |
| CVE-2021-25783 | HIGH | 7.2 | 1.1% | Dec 2, 2021 | Taocms v2.5Beta5 was discovered to contain a blind SQL injection vulnerability via the function Article Search. |
| CVE-2021-28236 | HIGH | 7.5 | 1.2% | Dec 2, 2021 | LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now