2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25745HIGH8.1A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec...
CVE-2021-25268HIGH8.4Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Fire...
CVE-2021-25267HIGH8.4Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall old...
CVE-2021-44057CRITICAL9.8An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, th...
CVE-2021-44056CRITICAL9.8An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, th...
CVE-2021-44055CRITICAL9.8An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this...
CVE-2021-44054MEDIUM6.1An open redirect vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero and QTS. If exploite...
CVE-2021-44053MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QTS, QuTS hero and QuTScloud....
CVE-2021-44052HIGH8.1An improper link resolution before file access ('Link Following') vulnerability has been reported to affect QNAP device ...
CVE-2021-44051HIGH8.8A command injection vulnerability has been reported to affect QNAP NAS running QuTScloud, QuTS hero and QTS. If exploite...
CVE-2021-43547HIGH8.2TwinOaks Computing CoreDX DDS versions prior to 5.9.1 are susceptible to exploitation when an attacker sends a specially...
CVE-2021-38693MEDIUM5.3A path traversal vulnerability has been reported to affect QNAP device running QuTScloud, QuTS hero, QTS, QVR Pro Applia...
CVE-2021-38487CRITICAL9.1RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker...
CVE-2021-38447HIGH7.5OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target de...
CVE-2021-38445CRITICAL9.8OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associate...
CVE-2021-38443CRITICAL9.8Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write ar...
CVE-2021-38441CRITICAL9.8Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker t...
CVE-2021-38439CRITICAL9.8All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or ...
CVE-2021-38435CRITICAL9.8RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocat...
CVE-2021-38433HIGH7.8RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 vulnerable to a stack-based buffer overflow, ...
CVE-2021-38429CRITICAL9.1OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target de...
CVE-2021-38427HIGH7.8RTI Connext DDS Professional and Connext DDS Secure Versions 4.2.x to 6.1.0 are vulnerable to a stack-based buffer overf...
CVE-2021-38425CRITICAL9.1eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially cra...
CVE-2021-38423CRITICAL9.8All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buff...
CVE-2021-39020MEDIUM5.3IBM Guardium Data Encryption (GDE) 4.0.0.7 and lower stores sensitive information in URL parameters. This may lead to in...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now