2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34870 | MEDIUM | 6.5 | 0.9% | Jan 25, 2022 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETG... |
| CVE-2021-34869 | HIGH | 8.8 | 0.4% | Jan 25, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-4... |
| CVE-2021-34868 | HIGH | 8.8 | 0.4% | Jan 25, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-4... |
| CVE-2021-34867 | HIGH | 8.2 | 0.4% | Jan 25, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.3-4... |
| CVE-2021-34866 | HIGH | 7.8 | 1.0% | Jan 25, 2022 | This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.14-rc3. An ... |
| CVE-2021-34865 | HIGH | 8.8 | 3.1% | Jan 25, 2022 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of multiple NETG... |
| CVE-2021-46089 | CRITICAL | 9.8 | 2.0% | Jan 25, 2022 | In JeecgBoot 3.0, there is a SQL injection vulnerability that can operate the database with root privileges. |
| CVE-2021-46033 | CRITICAL | 9.8 | 1.2% | Jan 25, 2022 | In ForestBlog, as of 2021-12-28, File upload can bypass verification. |
| CVE-2021-3850 | CRITICAL | 9.1 | 2.2% | Jan 25, 2022 | Authentication Bypass by Primary Weakness in GitHub repository adodb/adodb prior to 5.20.21. |
| CVE-2021-45847 | MEDIUM | 5.5 | 0.8% | Jan 25, 2022 | Several missing input validations in the 3MF parser component of Slic3r libslic3r 1.3.0 can each allow an attacker to ca... |
| CVE-2021-45846 | MEDIUM | 5.5 | 0.6% | Jan 25, 2022 | A flaw in the AMF parser of Slic3r libslic3r 1.3.0 allows an attacker to cause an application crash using a crafted AMF ... |
| CVE-2021-46113 | HIGH | 8.8 | 3.1% | Jan 25, 2022 | In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by ... |
| CVE-2021-45845 | HIGH | 7.8 | 1.9% | Jan 25, 2022 | The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbi... |
| CVE-2021-45844 | HIGH | 7.8 | 1.1% | Jan 25, 2022 | Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands... |
| CVE-2021-45803 | HIGH | 8.8 | 1.2% | Jan 25, 2022 | MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because this view parameter value is ... |
| CVE-2021-45802 | CRITICAL | 9.8 | 1.3% | Jan 25, 2022 | MartDevelopers iResturant 1.0 is vulnerable to SQL Injection. SQL Injection occurs because the email and phone parameter... |
| CVE-2021-45343 | MEDIUM | 5.5 | 0.9% | Jan 25, 2022 | In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the applicat... |
| CVE-2021-45342 | HIGH | 7.8 | 1.9% | Jan 25, 2022 | A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker ... |
| CVE-2021-45029 | CRITICAL | 9.8 | 6.0% | Jan 25, 2022 | Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and ... |
| CVE-2021-45341 | HIGH | 8.8 | 6.6% | Jan 25, 2022 | A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker ... |
| CVE-2021-45340 | MEDIUM | 6.5 | 0.9% | Jan 25, 2022 | In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows a... |
| CVE-2021-46483 | HIGH | 7.8 | 0.8% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via BooleanConstructor at src/jsiBool.c. |
| CVE-2021-46482 | HIGH | 7.8 | 0.8% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via NumberConstructor at src/jsiNumber.c. |
| CVE-2021-46481 | MEDIUM | 5.5 | 0.7% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a memory leak via linenoise at src/linenoise.c. |
| CVE-2021-46480 | MEDIUM | 5.5 | 0.7% | Jan 25, 2022 | Jsish v3.5.0 was discovered to contain a heap buffer overflow via jsiValueObjDelete in src/jsiEval.c. This vulnerability... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now