2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27419CRITICAL9.8uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memor...
CVE-2021-27417CRITICAL9.8eCosCentric eCosPro RTOS Versions 2.0.1 through 4.5.3 are vulnerable to integer wraparound in function calloc (an implem...
CVE-2021-27411MEDIUM6.5Micrium OS Versions 5.10.1 and prior are vulnerable to integer wrap-around in functions Mem_DynPoolCreate, Mem_DynPoolCr...
CVE-2021-22680CRITICAL9.8NXP MQX Versions 5.1 and prior are vulnerable to integer overflow in mem_alloc, _lwmem_alloc and _partition functions. T...
CVE-2021-29854HIGH7.2IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of...
CVE-2021-46440HIGH7.5Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4....
CVE-2021-22573HIGH7.3The vulnerability is that IDToken verifier does not verify if token is properly signed. Signature verification makes sur...
CVE-2021-22556HIGH7.8The Security Team discovered an integer overflow bug that allows an attacker with code execution to issue memory cache i...
CVE-2021-39390MEDIUM5.4Stored XSS in PartKeepr 1.4.0 Edit section in multiple api endpoints via name parameter.
CVE-2021-42165HIGH8.8MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing c...
CVE-2021-42218HIGH7.5OMPL v1.5.2 contains a memory leak in VFRRT.cpp
CVE-2021-41959HIGH7.5JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/...
CVE-2021-4138MEDIUM5.3Improved Host header checks to reject requests not sent to a well-known local hostname or IP, or the server-specified ho...
CVE-2021-42532HIGH7.8XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res...
CVE-2021-42531HIGH7.8XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res...
CVE-2021-42530HIGH7.8XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res...
CVE-2021-42529HIGH7.8XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res...
CVE-2021-42528MEDIUM5.5XMP Toolkit 2021.07 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially craft...
CVE-2021-41810MEDIUM4.8Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Ad...
CVE-2021-36844MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MyThemeShop WP Subscribe plugin <= 1.2.12 on W...
CVE-2021-3750HIGH8.2A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointe...
CVE-2021-3643CRITICAL9.1A flaw was found in sox 14.4.1. The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw a...
CVE-2021-29859MEDIUM6.8IBM ICP4A - User Management System Component (IBM Cloud Pak for Business Automation V21.0.3 through V21.0.3-IF008, V21.0...
CVE-2021-25102MEDIUM4.7The All In One WP Security & Firewall WordPress plugin before 4.4.11 does not validate, sanitise and escape the redirect...
CVE-2021-25086MEDIUM6.1The Advanced Page Visit Counter WordPress plugin before 6.1.2 does not sanitise and escape some input before outputting ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now