2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39173 | HIGH | 8.8 | 2.4% | Aug 27, 2021 | Cachet is an open source status page system. Prior to version 2.5.1 authenticated users, regardless of their privileges ... |
| CVE-2021-39172 | HIGH | 8.8 | 29.2% | Aug 27, 2021 | Cachet is an open source status page system. Prior to version 2.5.1, authenticated users, regardless of their privileges... |
| CVE-2021-39171 | HIGH | 7.5 | 1.3% | Aug 27, 2021 | Passport-SAML is a SAML 2.0 authentication provider for Passport, the Node.js authentication library. Prior to version 3... |
| CVE-2021-32759 | HIGH | 7.2 | 1.3% | Aug 27, 2021 | OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in ve... |
| CVE-2021-3264 | HIGH | 7.2 | 0.9% | Aug 27, 2021 | SQL Injection vulnerability in cxuucms 3.1 ivia the pid parameter in public/admin.php. |
| CVE-2021-28697 | HIGH | 7.8 | 0.3% | Aug 27, 2021 | grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pa... |
| CVE-2021-28233 | HIGH | 8.8 | 1.1% | Aug 27, 2021 | Heap-based Buffer Overflow vulnerability exists in ok-file-formats 1 via the ok_jpg_generate_huffman_table function in o... |
| CVE-2021-32758 | HIGH | 7.2 | 2.0% | Aug 27, 2021 | OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layou... |
| CVE-2021-23434 | HIGH | 8.6 | 1.9% | Aug 27, 2021 | This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-1525... |
| CVE-2021-36531 | HIGH | 8.8 | 1.1% | Aug 27, 2021 | ngiflib 0.4 has a heap overflow in GetByte() at ngiflib.c:70 in NGIFLIB_NO_FILE mode, GetByte() reads memory buffer with... |
| CVE-2021-36530 | HIGH | 8.8 | 1.1% | Aug 27, 2021 | ngiflib 0.4 has a heap overflow in GetByteStr() at ngiflib.c:108 in NGIFLIB_NO_FILE mode, GetByteStr() copy memory buffe... |
| CVE-2021-40153 | HIGH | 8.1 | 2.5% | Aug 27, 2021 | squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by ... |
| CVE-2021-35342 | HIGH | 7.5 | 1.1% | Aug 27, 2021 | The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender E... |
| CVE-2021-40142 | HIGH | 7.5 | 2.6% | Aug 27, 2021 | In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS)... |
| CVE-2021-29801 | HIGH | 7.8 | 0.3% | Aug 26, 2021 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain ... |
| CVE-2021-29487 | HIGH | 7.4 | 0.9% | Aug 26, 2021 | octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an a... |
| CVE-2021-30604 | HIGH | 8.8 | 2.5% | Aug 26, 2021 | Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-30603 | HIGH | 7.5 | 3.9% | Aug 26, 2021 | Data race in WebAudio in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2021-30602 | HIGH | 8.8 | 2.1% | Aug 26, 2021 | Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a mal... |
| CVE-2021-30601 | HIGH | 8.8 | 1.9% | Aug 26, 2021 | Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to ins... |
| CVE-2021-30600 | HIGH | 8.8 | 2.5% | Aug 26, 2021 | Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the ren... |
| CVE-2021-30599 | HIGH | 8.8 | 5.4% | Aug 26, 2021 | Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2021-30598 | HIGH | 8.8 | 7.0% | Aug 26, 2021 | Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside ... |
| CVE-2021-30593 | HIGH | 8.1 | 1.9% | Aug 26, 2021 | Out of bounds read in Tab Strip in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to inst... |
| CVE-2021-30592 | HIGH | 8.8 | 2.0% | Aug 26, 2021 | Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to in... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now