2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-37711HIGH8.8Versions prior to 6.4.3.1 contain an authenticated server-side request forgery vulnerability in file upload via URL. Ver...
CVE-2021-36281HIGH8.8Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment vulnerability. A low privile...
CVE-2021-36279HIGH7.8Dell EMC PowerScale OneFS versions 8.2.x - 9.2.x contain an incorrect permission assignment for critical resource vulner...
CVE-2021-32826HIGH8.1Proxyee-Down is open source proxy software. An attacker being able to provide an extension script (eg: through a MiTM at...
CVE-2021-38608HIGH7.8Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to ...
CVE-2021-21861HIGH8.8An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A...
CVE-2021-21860HIGH8.8An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A...
CVE-2021-21859HIGH8.8An exploitable integer truncation vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on A...
CVE-2021-37707HIGH7.5Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a vulnerability that allows manipulatio...
CVE-2021-22940HIGH7.5Node.js before 16.6.1, 14.17.5, and 12.22.5 is vulnerable to a use after free attack where an attacker might be able to ...
CVE-2021-22938HIGH7.2A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje...
CVE-2021-22937HIGH7.2A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write...
CVE-2021-22935HIGH7.2A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje...
CVE-2021-22934HIGH7.2A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Co...
CVE-2021-22932HIGH7.5An issue has been identified in the CTX269106 mitigation tool for Citrix ShareFile storage zones controller which causes...
CVE-2021-38758HIGH7.5Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.ph...
CVE-2021-35392HIGH7.5Realtek Jungle SDK version v2.x up to v3.4.14B provides a 'WiFi Simple Config' server that implements both UPnP and SSDP...
CVE-2021-33193HIGH7.5A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request spl...
CVE-2021-23423HIGH7.5This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing include, include...
CVE-2021-23422HIGH7.8This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Comma...
CVE-2021-3708HIGH7.8D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticate...
CVE-2021-38712HIGH7.5OneNav 0.9.12 allows Information Disclosure of the onenav.db3 contents. NOTE: the vendor's recommended solution is to bl...
CVE-2021-38711HIGH7.5In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.
CVE-2021-21815HIGH7.8A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs'...
CVE-2021-21814HIGH7.8Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the comman...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now