2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-33792HIGH7.8Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trail...
CVE-2021-29730HIGH8.8IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2021-33012HIGH8.6Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted c...
CVE-2021-27039HIGH7.8A maliciously crafted TIFF and PCX file can be forced to read and write beyond allocated boundaries when parsing the TIF...
CVE-2021-27038HIGH7.8A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a malici...
CVE-2021-27037HIGH7.8A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt...
CVE-2021-27036HIGH7.8A maliciously crafted PCX, PICT, RCL, TIF, BMP, PSD or TIFF file can be used to write beyond the allocated buffer while ...
CVE-2021-27035HIGH7.8A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be f...
CVE-2021-27034HIGH7.8A heap-based buffer overflow could occur while parsing PICT, PCX, RCL or TIFF files in Autodesk Design Review 2018, 2017...
CVE-2021-27033HIGH8.1A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability...
CVE-2021-30201HIGH7.5The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are...
CVE-2021-30120HIGH7.5Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforc...
CVE-2021-30117HIGH8.8The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the p...
CVE-2021-23405HIGH8.8This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId par...
CVE-2021-36155HIGH7.5LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote a...
CVE-2021-36154HIGH7.5HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of ma...
CVE-2021-36153HIGH7.5Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny servic...
CVE-2021-3637HIGH7.5A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in Roo...
CVE-2021-3612HIGH7.8An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1...
CVE-2021-3571HIGH7.1A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture a...
CVE-2021-3570HIGH8.8A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message betw...
CVE-2021-1585HIGH8.1A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote att...
CVE-2021-1576HIGH8.8Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an...
CVE-2021-1574HIGH8.8Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an...
CVE-2021-1359HIGH8.8A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now