2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23568CRITICAL9.8The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive m...
CVE-2021-23543CRITICAL9.8All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.
CVE-2021-23173MEDIUM4.3The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthor...
CVE-2021-22569MEDIUM5.5An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that woul...
CVE-2021-22060MEDIUM4.3In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user t...
CVE-2021-20048HIGH8.8A Stack-based buffer overflow in the SonicOS SessionID HTTP response header allows a remote authenticated attacker to ca...
CVE-2021-20046HIGH8.8A Stack-based buffer overflow in the SonicOS HTTP Content-Length response header allows a remote authenticated attacker ...
CVE-2021-38674MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect QTS, QuTS hero and QuTScloud. If exploited, this ...
CVE-2021-25743LOW3kubectl does not neutralize escape, meta or control sequences contained in the raw data it outputs to a terminal. This i...
CVE-2021-46044MEDIUM5.5A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1via ShiftMetaOffset.isra, which causes a Denial of Service (conte...
CVE-2021-46043MEDIUM5.5A Pointer Dereference Vulnerability exits in GPAC 1.0.1 in the gf_list_count function, which causes a Denial of Service.
CVE-2021-42841MEDIUM6.1Insta HMS before 12.4.10 is vulnerable to XSS because of improper validation of user-supplied input by multiple scripts....
CVE-2021-46042MEDIUM5.5A Pointer Dereference Vulnerability exists in GPAC 1.0.1 via the _fseeko function, which causes a Denial of Service.
CVE-2021-46041MEDIUM5.5A Segmentation Fault Vulnerability exists in GPAC 1.0.1 via the co64_box_new function, which causes a Denial of Service.
CVE-2021-46040MEDIUM5.5A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the finplace_shift_moov_meta_offsets function, which causes ...
CVE-2021-46039MEDIUM5.5A Pointer Dereference Vulnerabilty exists in GPAC 1.0.1 via the shift_chunk_offsets.part function, which causes a Denial...
CVE-2021-4194MEDIUM6.5bookstack is vulnerable to Improper Access Control
CVE-2021-43045HIGH7.5A vulnerability in the .NET SDK of Apache Avro allows an attacker to allocate excessive resources, potentially causing a...
CVE-2021-28715MEDIUM6.5Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multi...
CVE-2021-28714MEDIUM6.5Guest can force Linux netback driver to hog large amounts of kernel memory T[his CNA information record relates to multi...
CVE-2021-46079HIGH7.2An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attac...
CVE-2021-46078MEDIUM4.8An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. A remote attac...
CVE-2021-46075HIGH7.2A Privilege Escalation vulnerability exists in Sourcecodester Vehicle Service Management System 1.0. Staff account users...
CVE-2021-46074MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the...
CVE-2021-46073MEDIUM4.8A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now