2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3654MEDIUM6.1A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to ...
CVE-2021-3631MEDIUM6.3A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one ...
CVE-2021-3623MEDIUM6.1A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal val...
CVE-2021-38266HIGH7.5The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix p...
CVE-2021-23222MEDIUM5.9A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certif...
CVE-2021-23206HIGH7.8A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to exe...
CVE-2021-23192HIGH7.5A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, ...
CVE-2021-23191HIGH7.8A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() i...
CVE-2021-23180HIGH7.8A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to ex...
CVE-2021-46270LOW2.7JFrog Artifactory before 7.31.10, is vulnerable to Broken Access Control where a project admin user is able to list all ...
CVE-2021-45074MEDIUM5.4JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to de...
CVE-2021-41003MEDIUM6.1Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F...
CVE-2021-41002HIGH8.1Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aru...
CVE-2021-41001HIGH8.8An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Arub...
CVE-2021-41000HIGH8.8Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aru...
CVE-2021-38268MEDIUM6.5The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 befo...
CVE-2021-43070MEDIUM6.5Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and be...
CVE-2021-38996MEDIUM5.5IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel...
CVE-2021-44166MEDIUM4.1An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and ...
CVE-2021-45864MEDIUM5.5tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp...
CVE-2021-45863MEDIUM5.5tsMuxer git-2678966 was discovered to contain a heap-based buffer overflow via the function HevcUnit::updateBits in hevc...
CVE-2021-45861MEDIUM5.5There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277.
CVE-2021-45860MEDIUM5.5An integer overflow in DTSStreamReader::findFrame() of tsMuxer git-2678966 allows attackers to cause a Denial of Service...
CVE-2021-41652HIGH7.5Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
CVE-2021-41282HIGH8.8diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data abo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now