2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-22230HIGH7.2Improper code rendering while rendering merge requests could be exploited to submit malicious code. This vulnerability a...
CVE-2021-20780HIGH8.8Cross-site request forgery (CSRF) vulnerability in WPCS - WordPress Currency Switcher 1.1.6 and earlier allows remote at...
CVE-2021-20779HIGH8.8Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3....
CVE-2021-20739HIGH8.8WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, a...
CVE-2021-35039HIGH7.8kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONF...
CVE-2021-22229HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was...
CVE-2021-32740HIGH7.5Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncon...
CVE-2021-24451HIGH7.2The Export Users With Meta WordPress plugin before 0.6.5 did not escape the list of roles to export before using them in...
CVE-2021-24005HIGH7.5Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions befo...
CVE-2021-35331HIGH7.8In Tcl 8.6.11, a format string vulnerability in nmakehlp.c might allow code execution via a crafted file. NOTE: multiple...
CVE-2021-36148HIGH7.8An issue was discovered in ACRN before 2.5. dmar_free_irte in hypervisor/arch/x86/vtd.c allows an irte_alloc_bitmap buff...
CVE-2021-36147HIGH7.5An issue was discovered in ACRN before 2.5. It allows a devicemodel/hw/pci/virtio/virtio_net.c virtio_net_ping_rxq NULL ...
CVE-2021-36146HIGH7.5ACRN before 2.5 has a devicemodel/hw/pci/xhci.c NULL Pointer Dereference for a trb pointer.
CVE-2021-36145HIGH7.5The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.
CVE-2021-36144HIGH7.5The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/p...
CVE-2021-36143HIGH7.5ACRN before 2.5 has a hw/pci/virtio/virtio.c vq_endchains NULL Pointer Dereference.
CVE-2021-34527HIGH8.8A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file ...
CVE-2021-30557HIGH8.8Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install ...
CVE-2021-30556HIGH8.8Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap...
CVE-2021-30555HIGH8.8Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a ...
CVE-2021-30554HIGH8.8Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap co...
CVE-2021-27950HIGH8.8A SQL injection vulnerability in azurWebEngine in Sita AzurCMS through 1.2.3.12 allows an authenticated attacker to exec...
CVE-2021-3613HIGH7.8OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL confi...
CVE-2021-3606HIGH7.8OpenVPN before version 2.5.3 on Windows allows local users to load arbitrary dynamic loadable libraries via an OpenSSL c...
CVE-2021-36132HIGH8.8An issue was discovered in the FileImporter extension in MediaWiki through 1.36. For certain relaxed configurations of t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now