2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1889 | HIGH | 7.8 | 0.2% | Jul 13, 2021 | Possible buffer overflow due to lack of length check in Trusted Application in Snapdragon Auto, Snapdragon Compute, Snap... |
| CVE-2021-1888 | HIGH | 7.8 | 0.2% | Jul 13, 2021 | Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, ... |
| CVE-2021-1887 | HIGH | 7.5 | 0.6% | Jul 13, 2021 | An assertion can be reached in the WLAN subsystem while using the Wi-Fi Fine Timing Measurement protocol in Snapdragon W... |
| CVE-2021-1886 | HIGH | 7.8 | 0.2% | Jul 13, 2021 | Incorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon A... |
| CVE-2021-32727 | HIGH | 7.5 | 0.7% | Jul 12, 2021 | Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature ... |
| CVE-2021-24441 | HIGH | 8 | 1.3% | Jul 12, 2021 | The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the ... |
| CVE-2021-32705 | HIGH | 7.5 | 1.7% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the... |
| CVE-2021-29794 | HIGH | 7.5 | 0.7% | Jul 12, 2021 | IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expe... |
| CVE-2021-29792 | HIGH | 7.2 | 0.5% | Jul 12, 2021 | IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and ... |
| CVE-2021-33807 | HIGH | 7.5 | 14.1% | Jul 12, 2021 | Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData. |
| CVE-2021-30639 | HIGH | 7.5 | 6.9% | Jul 12, 2021 | A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part... |
| CVE-2021-32688 | HIGH | 8.8 | 2.3% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens... |
| CVE-2021-24015 | HIGH | 8.8 | 1.2% | Jul 12, 2021 | An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of Fo... |
| CVE-2021-36377 | HIGH | 7.5 | 0.6% | Jul 12, 2021 | Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation. |
| CVE-2021-32679 | HIGH | 8.8 | 1.4% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, fi... |
| CVE-2021-26090 | HIGH | 7.5 | 1.3% | Jul 12, 2021 | A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 a... |
| CVE-2021-26089 | HIGH | 7.8 | 0.4% | Jul 12, 2021 | An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitra... |
| CVE-2021-3547 | HIGH | 7.4 | 1.0% | Jul 12, 2021 | OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authenticatio... |
| CVE-2021-27293 | HIGH | 7.5 | 1.5% | Jul 12, 2021 | RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (R... |
| CVE-2021-22921 | HIGH | 7.8 | 7.4% | Jul 12, 2021 | Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions... |
| CVE-2021-20024 | HIGH | 8.1 | 0.6% | Jul 9, 2021 | Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a s... |
| CVE-2021-36367 | HIGH | 8.1 | 1.1% | Jul 9, 2021 | PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication resp... |
| CVE-2021-26106 | HIGH | 7.8 | 0.3% | Jul 9, 2021 | An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.... |
| CVE-2021-26100 | HIGH | 7.5 | 0.3% | Jul 9, 2021 | A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthentic... |
| CVE-2021-22129 | HIGH | 8.8 | 1.1% | Jul 9, 2021 | Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail befo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now