2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-27762CRITICAL9.8Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web ...
CVE-2021-44057CRITICAL9.8An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, th...
CVE-2021-44056CRITICAL9.8An improper authentication vulnerability has been reported to affect QNAP device running Video Station. If exploited, th...
CVE-2021-44055CRITICAL9.8An missing authorization vulnerability has been reported to affect QNAP device running Video Station. If exploited, this...
CVE-2021-38487CRITICAL9.1RTI Connext Professional versions 4.1 to 6.1.0, and Connext Micro versions 2.4 and later are vulnerable when an attacker...
CVE-2021-38445CRITICAL9.8OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associate...
CVE-2021-38443CRITICAL9.8Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write ar...
CVE-2021-38441CRITICAL9.8Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker t...
CVE-2021-38439CRITICAL9.8All versions of GurumDDS are vulnerable to heap-based buffer overflow, which may cause a denial-of-service condition or ...
CVE-2021-38435CRITICAL9.8RTI Connext DDS Professional and Connext DDS Secure Versions 4.2x to 6.1.0 not correctly calculate the size when allocat...
CVE-2021-38429CRITICAL9.1OCI OpenDDS versions prior to 3.18.1 are vulnerable when an attacker sends a specially crafted packet to flood target de...
CVE-2021-38425CRITICAL9.1eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially cra...
CVE-2021-38423CRITICAL9.8All versions of GurumDDS improperly calculate the size to be used when allocating the buffer, which may result in a buff...
CVE-2021-42242CRITICAL9.8A command execution vulnerability exists in jfinal_cms 5.0.1 via com.jflyfox.component.controller.Ueditor.
CVE-2021-41739CRITICAL9.8A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cy...
CVE-2021-42235CRITICAL9.8SQL injection in osTicket before 1.14.8 and 1.15.4 login and password reset process allows attackers to access the osTic...
CVE-2021-42185CRITICAL9.8wdja v2.1 is affected by a SQL injection vulnerability in the foreground search function.
CVE-2021-43163CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Ruijie Networks Ruijie RG-EW Series Routers up to ReyeeOS 1.55.191...
CVE-2021-27439CRITICAL9.8TencentOS-tiny version 3.1.0 is vulnerable to integer wrap-around in function 'tos_mmheap_alloc incorrect calculation of...
CVE-2021-27435CRITICAL9.8ARM mbed product Version 6.3.0 is vulnerable to integer wrap-around in malloc_wrapper function, which can lead to arbitr...
CVE-2021-27433CRITICAL9.8ARM mbed-ualloc memory library version 1.3.0 is vulnerable to integer wrap-around in function mbed_krbs, which can lead ...
CVE-2021-27431CRITICAL9.8ARM CMSIS RTOS2 versions prior to 2.1.3 are vulnerable to integer wrap-around inosRtxMemoryAlloc (local malloc equivalen...
CVE-2021-27427CRITICAL9.8RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead ...
CVE-2021-27425CRITICAL9.8Cesanta Software Mongoose-OS v2.17.0 is vulnerable to integer wrap-around in function mm_malloc. This improper memory as...
CVE-2021-27421CRITICAL9.8NXP MCUXpresso SDK versions prior to 2.8.2 are vulnerable to integer overflow in SDK_Malloc function, which could allow ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now