2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-37576HIGH7.8arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to c...
CVE-2021-32794HIGH7.5ArchiSteamFarm is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due...
CVE-2021-37394HIGH8.8In RPCMS v1.8 and below, attackers can interact with API and change variable "role" to "admin" to achieve admin user reg...
CVE-2021-31292HIGH7.5An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and...
CVE-2021-25804HIGH7.5A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the a...
CVE-2021-25803HIGH7.1A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows att...
CVE-2021-25802HIGH7.1A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attacker...
CVE-2021-25801HIGH7.1A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to ca...
CVE-2021-32789HIGH7.5woocommerce-gutenberg-products-block is a feature plugin for WooCommerce Gutenberg Blocks. An SQL injection vulnerabilit...
CVE-2021-33629HIGH7.5isula-build before 0.9.5-6 can cause a program crash, when building container images, some functions for processing exte...
CVE-2021-26824HIGH7.1DM FingerTool v1.19 in the DM PD065 Secure USB is susceptible to improper authentication by a replay attack, allowing lo...
CVE-2021-20337HIGH7.5IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that cou...
CVE-2021-33900HIGH7.5While investigating DIRSTUDIO-1219 it was noticed that configured StartTLS encryption was not applied when any SASL auth...
CVE-2021-37447HIGH8.1In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentdelete?file=/.. for file ...
CVE-2021-37444HIGH8.8NCH IVM Attendant v5.12 and earlier suffers from a directory traversal weakness upon uploading plugins in a ZIP archive....
CVE-2021-37443HIGH8.1NCH IVM Attendant v5.12 and earlier allows path traversal via the logdeleteselected check0 parameter for file deletion.
CVE-2021-37441HIGH8.8NCH Axon PBX v2.22 and earlier allows path traversal for file deletion via the logdelete?file=/.. substring.
CVE-2021-3663HIGH7.5firefly-iii is vulnerable to Improper Restriction of Excessive Authentication Attempts
CVE-2021-32783HIGH8.5Contour is a Kubernetes ingress controller using Envoy proxy. In Contour before version 1.17.1 a specially crafted Exter...
CVE-2021-25808HIGH7.8A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a cr...
CVE-2021-25201HIGH7.5SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL stateme...
CVE-2021-32785HIGH7.5mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co...
CVE-2021-3540HIGH7.2By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions...
CVE-2021-3198HIGH7.2By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivan...
CVE-2021-36222HIGH7.5ec_verify in kdc/kdc_preauth_ec.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.4 and 1....

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now