2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26619CRITICAL9.1An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can u...
CVE-2021-26618CRITICAL9.8An improper input validation leading to arbitrary file creation was discovered in ToWord of ToOffice. Remote attackers u...
CVE-2021-20325CRITICAL9.8Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5...
CVE-2021-20322HIGH7.4A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functional...
CVE-2021-20321MEDIUM4.7A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in s...
CVE-2021-20320MEDIUM5.5A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a l...
CVE-2021-20315MEDIUM6.1A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "...
CVE-2021-46372MEDIUM5.4Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to...
CVE-2021-46108MEDIUM5.4D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance config...
CVE-2021-41599HIGH8.8A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a...
CVE-2021-4120HIGH7.8snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability...
CVE-2021-44731HIGH7.8A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. Th...
CVE-2021-44730HIGH8.8snapd 2.54.2 did not properly validate the location of the snap-confine binary. A local attacker who can hardlink this b...
CVE-2021-3155MEDIUM5.5snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. ...
CVE-2021-46319CRITICAL9.8Remote Code Execution (RCE) vulnerability exists in D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-...
CVE-2021-46315CRITICAL9.8Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetWizardConfig.php in D-Link Router DIR-846 DIR846...
CVE-2021-46314CRITICAL9.8A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router...
CVE-2021-45382CRITICAL9.8A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L...
CVE-2021-46247HIGH7.5The use of a hard-coded cryptographic key significantly increases the possibility encrypted data may be recovered from A...
CVE-2021-39034HIGH7.5IBM MQ 9.1 LTS is vulnerable to a denial of service attack caused by an issue within the channel process. IBM X-Force ID...
CVE-2021-44868CRITICAL9.8A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do
CVE-2021-46368HIGH7.8TRIGONE Remote System Monitor 3.61 is vulnerable to an unquoted path service allowing local users to launch processes wi...
CVE-2021-43303CRITICAL9.8Buffer overflow in PJSUA API when calling pjsua_call_dump. An attacker-controlled 'buffer' argument may cause a buffer o...
CVE-2021-43302CRITICAL9.1Read out-of-bounds in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause...
CVE-2021-43301CRITICAL9.8Stack overflow in PJSUA API when calling pjsua_playlist_create. An attacker-controlled 'file_names' argument may cause a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now