2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-34408HIGH7.8The Zoom Client for Meetings for Windows in all versions before version 5.3.2 writes log files to a user writable direct...
CVE-2021-40108HIGH8.8An issue was discovered in Concrete CMS through 8.5.5. The Calendar is vulnerable to CSRF. ccm_token is not verified on ...
CVE-2021-3828HIGH7.5nltk is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3822HIGH7.5jsoneditor is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3820HIGH7.5inflect is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3819HIGH8.8firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-23243HIGH7.8In Oppo's battery application, the third-party SDK provides the function of loading a third-party Provider, which can be...
CVE-2021-40104HIGH7.5An issue was discovered in Concrete CMS through 8.5.5. There is an SVG sanitizer bypass.
CVE-2021-40103HIGH7.5An issue was discovered in Concrete CMS through 8.5.5. Path Traversal can lead to Arbitrary File Reading and SSRF.
CVE-2021-40097HIGH8.8An issue was discovered in Concrete CMS through 8.5.5. Authenticated path traversal leads to to remote code execution vi...
CVE-2021-0612HIGH7.8In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ...
CVE-2021-0611HIGH7.8In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ...
CVE-2021-0610HIGH7.8In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local ...
CVE-2021-34570HIGH7.5Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through spe...
CVE-2021-40981HIGH7.3ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the pu...
CVE-2021-31606HIGH7.5furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
CVE-2021-31605HIGH7.5furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This ca...
CVE-2021-34349HIGH7.2A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ...
CVE-2021-41617HIGH7sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio...
CVE-2021-40655HIGH7.5An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name...
CVE-2021-41504HIGH8An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authen...
CVE-2021-41503HIGH8DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authenticatio...
CVE-2021-2464HIGH7.8Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitab...
CVE-2021-40309HIGH8.8A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to ...
CVE-2021-28130HIGH7.8Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload w...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now