2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-35218HIGH8.8Deserialization of Untrusted Data in the Web Console Chart Endpoint can lead to remote code execution. An unauthorized a...
CVE-2021-35216HIGH8.8Insecure Deserialization of untrusted data remote code execution vulnerability was discovered in Patch Manager Orion Pla...
CVE-2021-35215HIGH8.8Insecure deserialization leading to Remote Code Execution was detected in the Orion Platform version 2020.2.5. Authentic...
CVE-2021-23426HIGH7.5This affects all versions of package Proto. It is possible to inject pollute the object property of an application using...
CVE-2021-35508HIGH8.8NMSAccess32.exe in TeraRecon AQNetClient 4.4.13 allows attackers to execute a malicious binary with SYSTEM privileges vi...
CVE-2021-39373HIGH7.8Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk manageme...
CVE-2021-38703HIGH8.8Wireless devices running certain Arcadyan-derived firmware (such as KPN Experia WiFi 1.00.15) do not properly sanitise u...
CVE-2021-39109HIGH7.5The renderWidgetResource resource in Atlasian Atlasboard before version 1.1.9 allows remote attackers to read arbitrary ...
CVE-2021-33582HIGH7.5Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input tha...
CVE-2021-36235HIGH7.8An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges c...
CVE-2021-22003HIGH7.5VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious ac...
CVE-2021-22029HIGH7.5VMware Workspace ONE UEM REST API contains a denial of service vulnerability. A malicious actor with access to /API/syst...
CVE-2021-39180HIGH8.8OpenOLAT is a web-based learning management system (LMS). A path traversal vulnerability exists in versions prior to 15....
CVE-2021-39176HIGH7.5detect-character-encoding is a package for detecting character encoding using ICU. In detect-character-encoding v0.3.0 a...
CVE-2021-36232HIGH8.8Improper Authorization in multiple functions in MIK.starlight 7.9.5.24363 allows an authenticated attacker to escalate p...
CVE-2021-36231HIGH8.8Deserialization of untrusted data in multiple functions in MIK.starlight 7.9.5.24363 allows authenticated remote attacke...
CVE-2021-39135HIGH7.8`@npmcli/arborist`, the library that calculates dependency trees and manages the node_modules folder hierarchy for the n...
CVE-2021-39134HIGH7.8`@npmcli/arborist`, the library that calculates dependency trees and manages the `node_modules` folder hierarchy for the...
CVE-2021-37713HIGH8.6The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite ...
CVE-2021-37712HIGH8.6The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite ...
CVE-2021-37701HIGH8.6The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite a...
CVE-2021-35212HIGH8.8An SQL injection Privilege Escalation Vulnerability was discovered in the Orion Platform reported by the ZDI Team. A bli...
CVE-2021-22944HIGH8A vulnerability found in UniFi Protect application V1.18.1 and earlier allows a malicious actor with a view-only role an...
CVE-2021-22684HIGH7.5Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memo...
CVE-2021-35223HIGH8.8The Serv-U File Server allows for events such as user login failures to be audited by executing a command. This command ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now