2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-26426HIGH7Windows User Account Profile Picture Elevation of Privilege Vulnerability
CVE-2021-26425HIGH7.8Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2021-26423HIGH7.5.NET Core and Visual Studio Denial of Service Vulnerability
CVE-2021-38604HIGH7.5In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_RE...
CVE-2021-38599HIGH7.5WAL-G before 1.1, when a non-libsodium build (e.g., one of the official binary releases published as GitHub Releases) is...
CVE-2021-38291HIGH7.5FFmpeg version (git commit de8e6e67e7523e48bb27ac224a0b446df05e1640) suffers from a an assertion failure at src/libavuti...
CVE-2021-27794HIGH7.8A vulnerability in the authentication mechanism of Brocade Fabric OS versions before Brocade Fabric OS v.9.0.1a, v8.2.3a...
CVE-2021-27792HIGH7.8The request handling functions in web management interface of Brocade Fabric OS versions before v9.0.1a, v8.2.3a, and v7...
CVE-2021-27790HIGH7.8The command ipfilter in Brocade Fabric OS before Brocade Fabric OS v.9.0.1a, v8.2.3, and v8.2.0_CBN4, and v7.4.2h uses u...
CVE-2021-38088HIGH7.8Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.
CVE-2021-38086HIGH7.8Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed loc...
CVE-2021-37841HIGH7.8Docker Desktop before 3.6.0 suffers from incorrect access control. If a low-privileged account is able to access the ser...
CVE-2021-38593HIGH7.5Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRaste...
CVE-2021-38592HIGH7.5Wasm3 0.5.0 has a heap-based buffer overflow in op_Const64 (called from EvaluateExpression and m3_LoadModule).
CVE-2021-38589HIGH8.1In cPanel before 96.0.13, scripts/fix-cpanel-perl does not properly restrict the overwriting of files (SEC-588).
CVE-2021-38588HIGH8.1In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).
CVE-2021-38587HIGH7.5In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).
CVE-2021-38585HIGH7.2The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
CVE-2021-38584HIGH7.2The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
CVE-2021-37627HIGH7.2Contao is an open source CMS that allows creation of websites and scalable web applications. In affected versions it is ...
CVE-2021-37626HIGH7.2Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it i...
CVE-2021-36770HIGH7.8Encode.pm, as distributed in Perl through 5.34.0, allows local users to gain privileges via a Trojan horse Encode::Confi...
CVE-2021-38571HIGH7.8An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows DLL hijacking, aka CNVD-C-2021-68000 and...
CVE-2021-38569HIGH7.5An issue was discovered in Foxit Reader and PhantomPDF before 10.1.4. It allows stack consumption via recursive function...
CVE-2021-38567HIGH7.5An issue was discovered in Foxit PDF Editor before 11.0.1 and PDF Reader before 11.0.1 on macOS. It mishandles missing d...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now