2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-46568HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C...
CVE-2021-46567HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C...
CVE-2021-46566HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C...
CVE-2021-46565HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C...
CVE-2021-46564HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C...
CVE-2021-46563HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C...
CVE-2021-46562HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation C...
CVE-2021-46082HIGH7.5Moxa TN-5900 v3.1 series routers, MGate 5109 v2.2 series protocol gateways, and MGate 5101-PBM-MN v2.1 series protocol g...
CVE-2021-46063CRITICAL9.1MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management ...
CVE-2021-46062HIGH7.1MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
CVE-2021-23702CRITICAL9.8The package object-extend from 0.0.0 are vulnerable to Prototype Pollution via object-extend.
CVE-2021-46037HIGH8.1MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
CVE-2021-46036CRITICAL9.8An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to ex...
CVE-2021-4093HIGH8.8A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KV...
CVE-2021-4091HIGH7.5A double-free was found in the way 389-ds-base handles virtual attributes context in persistent searches. An attacker co...
CVE-2021-4090HIGH7.1An out-of-bounds (OOB) memory write flaw was found in the NFSD in the Linux kernel. Missing sanity may lead to a write b...
CVE-2021-45401CRITICAL9.8A Command injection vulnerability exists in Tenda AC10U AC1200 Smart Dual-band Wireless Router AC10U V1.0 Firmware V15.0...
CVE-2021-44968HIGH7.8A Use after Free vulnerability exists in IOBit Advanced SystemCare 15 pro via requests sent in sequential order using th...
CVE-2021-3948MEDIUM6.3An incorrect default permissions vulnerability was found in the mig-controller. Due to an incorrect cluster namespaces h...
CVE-2021-3947MEDIUM5.5A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a maliciou...
CVE-2021-3930MEDIUM6.5An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands...
CVE-2021-3657CRITICAL9.8A flaw was found in mbsync versions prior to 1.4.4. Due to inadequate handling of extremely large (>=2GiB) IMAP literals...
CVE-2021-39026MEDIUM5.9IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, ca...
CVE-2021-38935HIGH7.5IBM Maximo Asset Management 7.6.1.2 does not require that users should have strong passwords by default, which makes it ...
CVE-2021-30650MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now