2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-4172MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository star7th/showdoc prior to 2.10.2.
CVE-2021-39480HIGH7.5Bingrep v0.8.5 was discovered to contain a memory allocation failure which can cause a Denial of Service (DoS).
CVE-2021-46313MEDIUM5.5The binary MP4Box in GPAC v1.0.1 was discovered to contain a segmentation fault via the function __memmove_avx_unaligned...
CVE-2021-46311MEDIUM5.5A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_destroy_routes () at scenegraph/vr...
CVE-2021-46244MEDIUM6.5A Divide By Zero vulnerability exists in HDF5 v1.13.1-1 vis the function H5T__complete_copy () at /hdf5/src/H5T.c. This ...
CVE-2021-46243MEDIUM6.5An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at ...
CVE-2021-46242HIGH8.8HDF5 v1.13.1-1 was discovered to contain a heap-use-after free via the component H5AC_unpin_entry.
CVE-2021-46240MEDIUM5.5A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_dump_vrml_sffield () at scene_manager...
CVE-2021-46239MEDIUM5.5The binary MP4Box in GPAC v1.1.0 was discovered to contain an invalid free vulnerability via the function gf_free () at ...
CVE-2021-46238MEDIUM5.5GPAC v1.1.0 was discovered to contain a stack overflow via the function gf_node_get_name () at scenegraph/base_scenegrap...
CVE-2021-46237MEDIUM5.5An untrusted pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegrap...
CVE-2021-46236MEDIUM5.5A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_sg_vrml_field_pointer_del () at scene...
CVE-2021-46234MEDIUM5.5A NULL pointer dereference vulnerability exists in GPAC v1.1.0 via the function gf_node_unregister () at scenegraph/base...
CVE-2021-36339HIGH7.8The Dell EMC Virtual Appliances before 9.2.2.2 contain undocumented user accounts. A local malicious user may potentiall...
CVE-2021-36338HIGH8Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious us...
CVE-2021-40595CRITICAL9.8SQL injection vulnerability in Sourcecodester Online Leave Management System v1 by oretnom23, allows attackers to execut...
CVE-2021-23664HIGH7.5The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing ...
CVE-2021-23631HIGH7.5This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of packa...
CVE-2021-23518CRITICAL9.8The package cached-path-relative before 1.1.0 are vulnerable to Prototype Pollution via the cache variable that is set a...
CVE-2021-23460HIGH7.5The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of...
CVE-2021-4032MEDIUM4.4A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c kvm_free_lapic when a failure allo...
CVE-2021-4001MEDIUM4.1A race condition was found in the Linux kernel's ebpf verifier between bpf_map_update_elem and bpf_map_freeze due to a m...
CVE-2021-44593HIGH8.1Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL inje...
CVE-2021-44464HIGH8.8Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across al...
CVE-2021-43355CRITICAL9.8Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the cl...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now