2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33792 | HIGH | 7.8 | 2.1% | Jul 9, 2021 | Foxit Reader before 10.1.4 and PhantomPDF before 10.1.4 have an out-of-bounds write via a crafted /Size key in the Trail... |
| CVE-2021-29730 | HIGH | 8.8 | 1.0% | Jul 9, 2021 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ... |
| CVE-2021-33012 | HIGH | 8.6 | 1.9% | Jul 9, 2021 | Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted c... |
| CVE-2021-27039 | HIGH | 7.8 | 1.6% | Jul 9, 2021 | A maliciously crafted TIFF and PCX file can be forced to read and write beyond allocated boundaries when parsing the TIF... |
| CVE-2021-27038 | HIGH | 7.8 | 1.8% | Jul 9, 2021 | A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a malici... |
| CVE-2021-27037 | HIGH | 7.8 | 1.6% | Jul 9, 2021 | A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt... |
| CVE-2021-27036 | HIGH | 7.8 | 1.7% | Jul 9, 2021 | A maliciously crafted PCX, PICT, RCL, TIF, BMP, PSD or TIFF file can be used to write beyond the allocated buffer while ... |
| CVE-2021-27035 | HIGH | 7.8 | 1.7% | Jul 9, 2021 | A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be f... |
| CVE-2021-27034 | HIGH | 7.8 | 2.2% | Jul 9, 2021 | A heap-based buffer overflow could occur while parsing PICT, PCX, RCL or TIFF files in Autodesk Design Review 2018, 2017... |
| CVE-2021-27033 | HIGH | 8.1 | 3.0% | Jul 9, 2021 | A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability... |
| CVE-2021-30201 | HIGH | 7.5 | 25.3% | Jul 9, 2021 | The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are... |
| CVE-2021-30120 | HIGH | 7.5 | 5.7% | Jul 9, 2021 | Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforc... |
| CVE-2021-30117 | HIGH | 8.8 | 72.1% | Jul 9, 2021 | The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the p... |
| CVE-2021-23405 | HIGH | 8.8 | 1.7% | Jul 9, 2021 | This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId par... |
| CVE-2021-36155 | HIGH | 7.5 | 2.1% | Jul 9, 2021 | LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote a... |
| CVE-2021-36154 | HIGH | 7.5 | 2.1% | Jul 9, 2021 | HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of ma... |
| CVE-2021-36153 | HIGH | 7.5 | 2.1% | Jul 9, 2021 | Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny servic... |
| CVE-2021-3637 | HIGH | 7.5 | 1.1% | Jul 9, 2021 | A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in Roo... |
| CVE-2021-3612 | HIGH | 7.8 | 0.7% | Jul 9, 2021 | An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1... |
| CVE-2021-3571 | HIGH | 7.1 | 1.9% | Jul 9, 2021 | A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture a... |
| CVE-2021-3570 | HIGH | 8.8 | 3.0% | Jul 9, 2021 | A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message betw... |
| CVE-2021-1585 | HIGH | 8.1 | 20.0% | Jul 8, 2021 | A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote att... |
| CVE-2021-1576 | HIGH | 8.8 | 1.1% | Jul 8, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an... |
| CVE-2021-1574 | HIGH | 8.8 | 1.7% | Jul 8, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco Business Process Automation (BPA) could allow an... |
| CVE-2021-1359 | HIGH | 8.8 | 1.9% | Jul 8, 2021 | A vulnerability in the configuration management of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now