2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-1889HIGH7.8Possible buffer overflow due to lack of length check in Trusted Application in Snapdragon Auto, Snapdragon Compute, Snap...
CVE-2021-1888HIGH7.8Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, ...
CVE-2021-1887HIGH7.5An assertion can be reached in the WLAN subsystem while using the Wi-Fi Fine Timing Measurement protocol in Snapdragon W...
CVE-2021-1886HIGH7.8Incorrect handling of pointers in trusted application key import mechanism could cause memory corruption in Snapdragon A...
CVE-2021-32727HIGH7.5Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature ...
CVE-2021-24441HIGH8The Sign-up Sheets WordPress plugin before 1.0.14 does not not sanitise or validate the Sheet title when generating the ...
CVE-2021-32705HIGH7.5Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the...
CVE-2021-29794HIGH7.5IBM Tivoli Netcool/Impact 7.1.0.20 and 7.1.0.21 uses an insecure SSH server configuration which enables weaker than expe...
CVE-2021-29792HIGH7.2IBM Event Streams 10.0, 10.1, 10.2, and 10.3 could allow a user the CA private key to create their own certificates and ...
CVE-2021-33807HIGH7.5Cartadis Gespage through 8.2.1 allows Directory Traversal in gespage/doDownloadData and gespage/webapp/doDownloadData.
CVE-2021-30639HIGH7.5A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part...
CVE-2021-32688HIGH8.8Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens...
CVE-2021-24015HIGH8.8An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of Fo...
CVE-2021-36377HIGH7.5Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
CVE-2021-32679HIGH8.8Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, fi...
CVE-2021-26090HIGH7.5A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 a...
CVE-2021-26089HIGH7.8An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitra...
CVE-2021-3547HIGH7.4OpenVPN 3 Core Library version 3.6 and 3.6.1 allows a man-in-the-middle attacker to bypass the certificate authenticatio...
CVE-2021-27293HIGH7.5RestSharp < 106.11.8-alpha.0.13 uses a regular expression which is vulnerable to Regular Expression Denial of Service (R...
CVE-2021-22921HIGH7.8Node.js before 16.4.1, 14.17.2, and 12.22.2 is vulnerable to local privilege escalation attacks under certain conditions...
CVE-2021-20024HIGH8.1Multiple Out-of-Bound read vulnerability in SonicWall Switch when handling LLDP Protocol allows an attacker to cause a s...
CVE-2021-36367HIGH8.1PuTTY through 0.75 proceeds with establishing an SSH session even if it has never sent a substantive authentication resp...
CVE-2021-26106HIGH7.8An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6....
CVE-2021-26100HIGH7.5A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthentic...
CVE-2021-22129HIGH8.8Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail befo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now