2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-39204HIGH7.5Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, incorrectly handles resetting...
CVE-2021-39162HIGH8.6Pomerium is an open source identity-aware access proxy. Envoy, which Pomerium is based on, can abnormally terminate if a...
CVE-2021-38324HIGH7.5The SP Rental Manager WordPress plugin is vulnerable to SQL Injection via the orderby parameter found in the ~/user/shor...
CVE-2021-25465HIGH7An improper scheme check vulnerability in Samsung Themes prior to version 5.2.01 allows attackers to perform Man-in-the-...
CVE-2021-25461HIGH7.8An improper length check in APAService prior to SMR Sep-2021 Release 1 results in stack based Buffer Overflow.
CVE-2021-28912HIGH7.2BAB TECHNOLOGIE GmbH eibPort V3. Each device has its own unique hard coded and weak root SSH key passphrase known as 'ei...
CVE-2021-28910HIGH7.5BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 contains basic SSRF vulnerability. It allow unauthenticated attacker...
CVE-2021-32487HIGH7.5In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of ser...
CVE-2021-32486HIGH7.5In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of ser...
CVE-2021-32485HIGH7.5In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of ser...
CVE-2021-32484HIGH7.5In modem 2G RRM, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of ser...
CVE-2021-38723HIGH8.8FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items
CVE-2021-3761HIGH7.5Any CA issuer in the RPKI can trick OctoRPKI prior to 1.3.0 into emitting an invalid VRP "MaxLength" value, causing RTR ...
CVE-2021-28498HIGH7.8In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, user enable passwords ...
CVE-2021-28497HIGH7.8In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditio...
CVE-2021-28494HIGH8.8In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditio...
CVE-2021-28493HIGH7.8In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditio...
CVE-2021-40222HIGH7.2Rittal CMC PU III Web management Version affected: V3.11.00_2. Version fixed: V3.17.10 is affected by a remote code exec...
CVE-2021-39459HIGH7.2Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS u...
CVE-2021-26603HIGH7.8A heap overflow issue was found in ARK library of bandisoft Co., Ltd when the Ark_DigPathA function parsed a file path. ...
CVE-2021-30295HIGH7.8Possible heap overflow due to improper validation of local variable while storing current task information locally in Sn...
CVE-2021-30290HIGH7Possible null pointer dereference due to race condition between timeline fence signal and time line fence destroy in Sna...
CVE-2021-1974HIGH7.5Possible buffer over read due to lack of alignment between map or unmap length of IPA SMMU and WLAN SMMU in Snapdragon A...
CVE-2021-1971HIGH7.5Possible assertion due to lack of physical layer state validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Con...
CVE-2021-1952HIGH7.8Possible buffer over read occurs due to lack of length check of request buffer in Snapdragon Auto, Snapdragon Compute, S...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now