2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-43581HIGH8.8An Out-of-Bounds Read vulnerability exists when reading a U3D file using Open Design Alliance PRC SDK before 2022.11. Th...
CVE-2021-43557HIGH7.5The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full...
CVE-2021-38146HIGH7.5The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary ...
CVE-2021-28710HIGH8.8certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structure...
CVE-2021-23217HIGH7.5NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with eleva...
CVE-2021-23201HIGH7.5NVIDIA GPU and Tegra hardware contain a vulnerability in an internal microcontroller, which may allow a user with elevat...
CVE-2021-36321HIGH7.5Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an improper input validation vulnerability. A remote...
CVE-2021-36307HIGH8.8Networking OS10, versions prior to October 2021 with RESTCONF API enabled, contains a privilege escalation vulnerability...
CVE-2021-34358HIGH8.8We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and la...
CVE-2021-21898HIGH8.8A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-...
CVE-2021-44038HIGH7.8An issue was discovered in Quagga through 1.2.4. Unsafe chown/chmod operations in the suggested spec file allow users (w...
CVE-2021-43555HIGH7.8mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may ...
CVE-2021-42254HIGH7.8BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions...
CVE-2021-22970HIGH7.5Concrete CMS (formerly concrete5) versions 8.5.6 and below and version 9.0.0 allow local IP importing causing the system...
CVE-2021-22968HIGH7.2A bypass of adding remote files in Concrete CMS (previously concrete5) File Manager leads to remote code execution in Co...
CVE-2021-22967HIGH7.5In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowe...
CVE-2021-22966HIGH8.8Privilege escalation from Editor to Admin using Groups in Concrete CMS versions 8.5.6 and below. If a group is granted "...
CVE-2021-22965HIGH7.5A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial ...
CVE-2021-22951HIGH7.5Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) p...
CVE-2021-21900HIGH8.8A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f...
CVE-2021-21899HIGH8.8A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2...
CVE-2021-41569HIGH7.5SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the app...
CVE-2021-44037HIGH7.5Team Password Manager (aka TeamPasswordManager) before 10.135.236 allows password-reset poisoning.
CVE-2021-44036HIGH8.8Team Password Manager (aka TeamPasswordManager) before 10.135.236 has a CSRF vulnerability during import.
CVE-2021-3962HIGH7.8A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert proce...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now