2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37576 | HIGH | 7.8 | 0.6% | Jul 26, 2021 | arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to c... |
| CVE-2021-32794 | HIGH | 7.5 | 1.0% | Jul 26, 2021 | ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due... |
| CVE-2021-37394 | HIGH | 8.8 | 1.2% | Jul 26, 2021 | In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user reg... |
| CVE-2021-31292 | HIGH | 7.5 | 2.6% | Jul 26, 2021 | An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and... |
| CVE-2021-25804 | HIGH | 7.5 | 1.8% | Jul 26, 2021 | A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the a... |
| CVE-2021-25803 | HIGH | 7.1 | 0.7% | Jul 26, 2021 | A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows att... |
| CVE-2021-25802 | HIGH | 7.1 | 0.7% | Jul 26, 2021 | A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attacker... |
| CVE-2021-25801 | HIGH | 7.1 | 1.5% | Jul 26, 2021 | A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to ca... |
| CVE-2021-32789 | HIGH | 7.5 | 17.2% | Jul 26, 2021 | woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerabilit... |
| CVE-2021-33629 | HIGH | 7.5 | 1.0% | Jul 26, 2021 | isula-build before 0.9.5-6 can cause a program crash, when building container images, some functions for processing exte... |
| CVE-2021-26824 | HIGH | 7.1 | 0.4% | Jul 26, 2021 | DM FingerTool v1.19 in the DM PD065 Secure USB is susceptible to improper authentication by a replay attack, allowing lo... |
| CVE-2021-20337 | HIGH | 7.5 | 0.7% | Jul 26, 2021 | IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that cou... |
| CVE-2021-33900 | HIGH | 7.5 | 0.8% | Jul 26, 2021 | While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL auth... |
| CVE-2021-37447 | HIGH | 8.1 | 1.6% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file ... |
| CVE-2021-37444 | HIGH | 8.8 | 1.9% | Jul 25, 2021 | NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive.... |
| CVE-2021-37443 | HIGH | 8.1 | 1.2% | Jul 25, 2021 | NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion. |
| CVE-2021-37441 | HIGH | 8.8 | 1.5% | Jul 25, 2021 | NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring. |
| CVE-2021-3663 | HIGH | 7.5 | 0.7% | Jul 25, 2021 | firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts |
| CVE-2021-32783 | HIGH | 8.5 | 1.2% | Jul 23, 2021 | Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted Exter... |
| CVE-2021-25808 | HIGH | 7.8 | 1.2% | Jul 23, 2021 | A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a cr... |
| CVE-2021-25201 | HIGH | 7.5 | 1.5% | Jul 23, 2021 | SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL stateme... |
| CVE-2021-32785 | HIGH | 7.5 | 2.7% | Jul 22, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-3540 | HIGH | 7.2 | 3.3% | Jul 22, 2021 | By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions... |
| CVE-2021-3198 | HIGH | 7.2 | 3.3% | Jul 22, 2021 | By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivan... |
| CVE-2021-36222 | HIGH | 7.5 | 10.3% | Jul 22, 2021 | ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1.... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now