2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-21813HIGH7.8Within the function HandleFileArg the argument filepattern is under control of the user who passes it in from the comman...
CVE-2021-21812HIGH7.8A stack-based buffer overflow vulnerability exists in the command-line-parsing HandleFileArg functionality of AT&T Labs’...
CVE-2021-38623HIGH7.5The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service ...
CVE-2021-36793HIGH7.5The routes (aka Extbase Yaml Routes) extension before 2.1.1 for TYPO3, when CsrfTokenViewHelper is used, allows Sensitiv...
CVE-2021-36792HIGH7.2The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various ap...
CVE-2021-36786HIGH7.5The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows Sensitive Data Exposure of API credent...
CVE-2021-37693HIGH7.5Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when ...
CVE-2021-34398HIGH7.8NVIDIA DCGM, all versions prior to 2.2.9, contains a vulnerability in the DIAG module where any user can inject shared l...
CVE-2021-37349HIGH7.8Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because cleaner.php does not sanitise input r...
CVE-2021-37348HIGH7.5Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation of a pathname in index....
CVE-2021-37347HIGH7.8Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the d...
CVE-2021-37345HIGH7.8Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because xi-sys.cfg is being imported from the...
CVE-2021-37343HIGH8.8A path traversal vulnerability exists in Nagios XI below version 5.8.5 AutoDiscovery component and could lead to post au...
CVE-2021-38614HIGH7.5Polipo through 1.1.1, when NDEBUG is used, allows a heap-based buffer overflow during parsing of a Range header. NOTE: T...
CVE-2021-37682HIGH7.1TensorFlow is an end-to-end open source platform for machine learning. In affected versions all TFLite operations that u...
CVE-2021-37679HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions it is possible to nest a `tf...
CVE-2021-37678HIGH8.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions TensorFlow and Keras can be ...
CVE-2021-37665HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation...
CVE-2021-37663HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions due to incomplete validation...
CVE-2021-37681HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation of SVDF i...
CVE-2021-37676HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefi...
CVE-2021-37671HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefi...
CVE-2021-37667HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefi...
CVE-2021-37666HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions an attacker can cause undefi...
CVE-2021-37652HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In affected versions the implementation for `tf.r...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now