2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44209MEDIUM6.1OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
CVE-2021-44208MEDIUM6.1OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
CVE-2021-26601HIGH8.1ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.
CVE-2021-26600CRITICAL9.8ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= inste...
CVE-2021-26599CRITICAL9.8ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.
CVE-2021-26598MEDIUM5.3ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated atta...
CVE-2021-44127CRITICAL9.8In DLink DAP-1360 F1 firmware version <=v6.10 in the "webupg" binary, an attacker can use the "file" parameter to execut...
CVE-2021-40906MEDIUM6.1CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in...
CVE-2021-40905HIGH8.8The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uplo...
CVE-2021-40904HIGH8.8The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dok...
CVE-2021-44683HIGH8.2The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the JavaScript window.open functi...
CVE-2021-44905HIGH8.2Incorrect permissions in the Bluetooth Services in the Fortessa FTBTLD Smart Lock as of 12-13-2022 allows a remote attac...
CVE-2021-4203MEDIUM6.8A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race w...
CVE-2021-4202HIGH7A use-after-free flaw was found in nci_request in net/nfc/nci/core.c in NFC Controller Interface (NCI) in the Linux kern...
CVE-2021-4157HIGH8An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users...
CVE-2021-4147MEDIUM6.5A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on t...
CVE-2021-44768MEDIUM5.5Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specifi...
CVE-2021-44477HIGH7.5GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD paramete...
CVE-2021-44462HIGH7.1This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionR...
CVE-2021-3941MEDIUM6.5In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x -...
CVE-2021-3933MEDIUM5.5An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could caus...
CVE-2021-3814HIGH7.5It was found that 3scale's APIdocs does not validate the access token, in the case of invalid token, it uses session aut...
CVE-2021-3582MEDIUM6.5A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRD...
CVE-2021-3567HIGH7.5A flaw was found in Caribou due to a regression of CVE-2020-25712 fix. An attacker could use this flaw to bypass screen-...
CVE-2021-3422HIGH7.5The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial-of-service in Splunk En...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now