2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34870MEDIUM6.5This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG...
CVE-2021-34869HIGH8.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-4...
CVE-2021-34868HIGH8.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-4...
CVE-2021-34867HIGH8.2This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-4...
CVE-2021-34866HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An ...
CVE-2021-34865HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETG...
CVE-2021-46089CRITICAL9.8In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges.
CVE-2021-46033CRITICAL9.8In ForestBlog, as of 2021-12-28, File upload can bypass verification.
CVE-2021-3850CRITICAL9.1Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21.
CVE-2021-45847MEDIUM5.5Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to ca...
CVE-2021-45846MEDIUM5.5A flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF ...
CVE-2021-46113HIGH8.8In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by ...
CVE-2021-45845HIGH7.8The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbi...
CVE-2021-45844HIGH7.8Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands...
CVE-2021-45803HIGH8.8MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is ...
CVE-2021-45802CRITICAL9.8MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter...
CVE-2021-45343MEDIUM5.5In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the applicat...
CVE-2021-45342HIGH7.8A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker ...
CVE-2021-45029CRITICAL9.8Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and ...
CVE-2021-45341HIGH8.8A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker ...
CVE-2021-45340MEDIUM6.5In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows a...
CVE-2021-46483HIGH7.8Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c.
CVE-2021-46482HIGH7.8Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c.
CVE-2021-46481MEDIUM5.5Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c.
CVE-2021-46480MEDIUM5.5Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now