2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42859HIGH7.5A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inco...
CVE-2021-42692MEDIUM6.5There is a stack-overflow vulnerability in tinytoml v0.4 that can cause a crash or DoS.
CVE-2021-27783MEDIUM6.5User generated PPKG file for Bulk Enroll may have unencrypted sensitive information exposed.
CVE-2021-27779CRITICAL9.1VersionVault Express exposes sensitive information that an attacker can use to impersonate the server or eavesdrop on co...
CVE-2021-44719HIGH8.4Docker Desktop 4.3.0 has Incorrect Access Control.
CVE-2021-35487MEDIUM6.5Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection atta...
CVE-2021-32997HIGH7.5The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 Sys...
CVE-2021-32989MEDIUM6.1When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns erro...
CVE-2021-32966HIGH7.5Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text t...
CVE-2021-44974MEDIUM5.5radareorg radare2 version 5.5.2 is vulnerable to NULL Pointer Dereference via libr/bin/p/bin_symbols.c binary symbol par...
CVE-2021-42614HIGH7.8A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or ...
CVE-2021-42613HIGH7.8A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly hav...
CVE-2021-42612HIGH7.8A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly...
CVE-2021-3717HIGH7.8A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may l...
CVE-2021-3629MEDIUM5.9A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potenti...
CVE-2021-3597MEDIUM5.9A flaw was found in undertow. The HTTP2SourceChannel fails to write the final frame under some circumstances, resulting ...
CVE-2021-32969HIGH7.8Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result...
CVE-2021-32965HIGH7.8Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to rem...
CVE-2021-32964MEDIUM5.3The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to a path traversal attack, which may allow an a...
CVE-2021-32962MEDIUM6.1The AGG Software Web Server version 4.0.40.1014 and prior is vulnerable to cross-site scripting, which may allow an atta...
CVE-2021-4230HIGH7.5A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /ba...
CVE-2021-4229HIGH8.8A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the cryp...
CVE-2021-45915CRITICAL9.8In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a cookie value. This allows the ...
CVE-2021-45914CRITICAL9.8In LuxSoft LuxCal Web Calendar before 5.2.0, an unauthenticated attacker can manipulate a POST request. This allows the ...
CVE-2021-44975MEDIUM5.5radareorg radare2 5.5.2 is vulnerable to Buffer Overflow via /libr/core/anal_objc.c mach-o parser.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now