2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-46490MEDIUM5.5Jsish v3.5.0 was discovered to contain a SEGV vulnerability via NumberConstructor at src/jsiNumber.c. This vulnerability...
CVE-2021-46489MEDIUM5.5Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_DecrRefCount in src/jsiValue.c. This vulnerability ...
CVE-2021-46488MEDIUM5.5Jsish v3.5.0 was discovered to contain a SEGV vulnerability via jsi_ArrayConcatCmd at src/jsiArray.c. This vulnerability...
CVE-2021-46487MEDIUM5.5Jsish v3.5.0 was discovered to contain a SEGV vulnerability via /lib/x86_64-linux-gnu/libc.so.6+0x18e506. This vulnerabi...
CVE-2021-46486MEDIUM5.5Jsish v3.5.0 was discovered to contain a SEGV vulnerability via jsi_ArraySpliceCmd at src/jsiArray.c. This vulnerability...
CVE-2021-46485MEDIUM5.5Jsish v3.5.0 was discovered to contain a SEGV vulnerability via Jsi_ValueIsNumber at src/jsiValue.c. This vulnerability ...
CVE-2021-46484MEDIUM5.5Jsish v3.5.0 was discovered to contain a heap-use-after-free via Jsi_IncrRefCount in src/jsiValue.c. This vulnerability ...
CVE-2021-46428CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 ( and previous versi...
CVE-2021-46427CRITICAL9.8An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Mast...
CVE-2021-46377CRITICAL9.8There is a front-end sql injection vulnerability in cszcms 1.2.9 via cszcms/controllers/Member.php#viewUser
CVE-2021-46102HIGH7.5From version 0.2.14 to 0.2.16 for Solana rBPF, function "relocate" in the file src/elf.rs has an integer overflow bug be...
CVE-2021-46097HIGH8.8Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log
CVE-2021-46088HIGH7.2Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" rol...
CVE-2021-46065MEDIUM4.8A Cross-site scripting (XSS) vulnerability in Secondary Email Field in Zoho ManageEngine ServiceDesk Plus 11.3 Build 113...
CVE-2021-28096MEDIUM5.3An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy con...
CVE-2021-44795MEDIUM5.3Single Connect does not perform an authorization check when using the "sc-assigned-credential-ui" module. A remote attac...
CVE-2021-44794MEDIUM5.3Single Connect does not perform an authorization check when using the "sc-diagnostic-ui" module. A remote attacker could...
CVE-2021-44793HIGH8.6Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exp...
CVE-2021-44792MEDIUM5.3Single Connect does not perform an authorization check when using the "log-monitor" module. A remote attacker could expl...
CVE-2021-44121Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-41166MEDIUM5.3The Nextcloud Android app is the Android client for Nextcloud, a self-hosted productivity platform. An issue in versions...
CVE-2021-32849HIGH8.8Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitr...
CVE-2021-32841MEDIUM5.3SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.3.0 and prior to version 1.3.3, a che...
CVE-2021-32842MEDIUM5.3SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Starting version 1.0.0 and prior to version 1.3.3, a che...
CVE-2021-32840CRITICAL9.8SharpZipLib (or #ziplib) is a Zip, GZip, Tar and BZip2 library. Prior to version 1.3.3, a TAR file entry `../evil.txt` m...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now