2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43300CRITICAL9.8Stack overflow in PJSUA API when calling pjsua_recorder_create. An attacker-controlled 'filename' argument may cause a b...
CVE-2021-43299CRITICAL9.8Stack overflow in PJSUA API when calling pjsua_player_create. An attacker-controlled 'filename' argument may cause a buf...
CVE-2021-3242CRITICAL9.8DuxCMS v3.1.3 was discovered to contain a SQL injection vulnerability via the component s/tools/SendTpl/index?keyword=.
CVE-2021-3781CRITICAL9.9A trivial sandbox (enabled with the `-dSAFER` option) escape flaw was found in the ghostscript interpreter by injecting ...
CVE-2021-3773CRITICAL9.8A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for furthe...
CVE-2021-3760HIGH7.8A flaw was found in the Linux kernel. A use-after-free vulnerability in the NFC stack can lead to a threat to confidenti...
CVE-2021-3753MEDIUM4.7A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bo...
CVE-2021-3752HIGH7.1A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket an...
CVE-2021-3578HIGH7.8A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised s...
CVE-2021-3560HIGH7.8It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile...
CVE-2021-4220Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-4134MEDIUM4.9The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameteriza...
CVE-2021-4106HIGH7.8A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges....
CVE-2021-3648Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-3530. Reason: This candidate is a reservation du...
CVE-2021-3557MEDIUM6.5A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created Servi...
CVE-2021-3551HIGH7.8A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the...
CVE-2021-39301HIGH8.8Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation o...
CVE-2021-39300HIGH8.8Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation o...
CVE-2021-39299HIGH8.8Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation o...
CVE-2021-39298HIGH8.8A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileg...
CVE-2021-39297HIGH8.8Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation o...
CVE-2021-23682CRITICAL9.8This affects the package litespeed.js before 0.3.12; the package appwrite/server-ce from 0.12.0 and before 0.12.2, befor...
CVE-2021-22050HIGH7.5ESXi contains a slow HTTP POST denial-of-service vulnerability in rhttpproxy. A malicious actor with network access to E...
CVE-2021-22043HIGH7.5VMware ESXi contains a TOCTOU (Time-of-check Time-of-use) vulnerability that exists in the way temporary files are handl...
CVE-2021-22042HIGH7.8VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd authorization tickets. A...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now