2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-39173HIGH8.8Cachet is an open source status page system. Prior to version 2.5.1 authenticated users, regardless of their privileges ...
CVE-2021-39172HIGH8.8Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges...
CVE-2021-39171HIGH7.5Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3...
CVE-2021-32759HIGH7.2OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in ve...
CVE-2021-3264HIGH7.2SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php.
CVE-2021-28697HIGH7.8grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pa...
CVE-2021-28233HIGH8.8Heap-based Buffer Overflow vulnerability exists in ok-file-formats 1 via the ok_jpg_generate_huffman_table function in o...
CVE-2021-32758HIGH7.2OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layou...
CVE-2021-23434HIGH8.6This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-1525...
CVE-2021-36531HIGH8.8ngiflib 0.4 has a heap overflow in GetByte() at ngiflib.c:70 in NGIFLIB_NO_FILE mode, GetByte() reads memory buffer with...
CVE-2021-36530HIGH8.8ngiflib 0.4 has a heap overflow in GetByteStr() at ngiflib.c:108 in NGIFLIB_NO_FILE mode, GetByteStr() copy memory buffe...
CVE-2021-40153HIGH8.1squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by ...
CVE-2021-35342HIGH7.5The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender E...
CVE-2021-40142HIGH7.5In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS)...
CVE-2021-29801HIGH7.8IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain ...
CVE-2021-29487HIGH7.4octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an a...
CVE-2021-30604HIGH8.8Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap co...
CVE-2021-30603HIGH7.5Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corr...
CVE-2021-30602HIGH8.8Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a mal...
CVE-2021-30601HIGH8.8Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to ins...
CVE-2021-30600HIGH8.8Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the ren...
CVE-2021-30599HIGH8.8Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside ...
CVE-2021-30598HIGH8.8Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside ...
CVE-2021-30593HIGH8.1Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to inst...
CVE-2021-30592HIGH8.8Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to in...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now