2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-43312HIGH7.5A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The ...
CVE-2021-43311HIGH7.5A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in ...
CVE-2021-3674HIGH7.8A flaw was found in rizin. The create_section_from_phdr function allocates space for ELF section data by processing the ...
CVE-2021-46877HIGH7.5jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of serv...
CVE-2021-21548HIGH7.4 Dell EMC Unisphere for PowerMax versions before 9.1.0.27, Dell EMC Unisphere for PowerMax Virtual Appliance versions be...
CVE-2021-31637HIGH7.8An issue found in UwAmp v.1.1, 1.2, 1.3, 2.0, 2.1, 2.2, 2.2.1, 3.0.0, 3.0.1, 3.0.2 allows a remote attacker to execute a...
CVE-2021-34125HIGH7.5An issue discovered in Yuneec Mantis Q and PX4-Autopilot v 1.11.3 and below allow attacker to gain access to sensitive i...
CVE-2021-33639HIGH7.5REMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified.
CVE-2021-4331HIGH8.8The Plus Addons for Elementor plugin for WordPress is vulnerable to privilege escalation in versions up to, and includin...
CVE-2021-4330HIGH8.8The Envato Elements & Download and Template Kit – Import plugins for WordPress are vulnerable to arbitrary file uploads ...
CVE-2021-36396HIGH7.5In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictio...
CVE-2021-36395HIGH7.5In Moodle, the file repository's URL parsing required additional recursion handling to mitigate the risk of recursion de...
CVE-2021-4326HIGH7.8A vulnerability in Imperative framework which allows already-privileged local actors to execute arbitrary shell commands...
CVE-2021-3855HIGH8.8Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Manag...
CVE-2021-35290HIGH7.2File Upload vulnerability in balerocms-src 0.8.3 allows remote attackers to run arbitrary code via rich text editor on /...
CVE-2021-34249HIGH7.5SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive informatio...
CVE-2021-34167HIGH8.8Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via...
CVE-2021-32848HIGH7.5Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide...
CVE-2021-32846HIGH7.8HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107, function `pci_vts...
CVE-2021-32845HIGH7.8HyperKit is a toolkit for embedding hypervisor capabilities in an application. In versions 0.20210107 and prior of Hyper...
CVE-2021-3172HIGH8.1An issue in Php-Fusion v9.03.90 fixed in v9.10.00 allows authenticated attackers to cause a Distributed Denial of Servic...
CVE-2021-34164HIGH8.8Permissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set p...
CVE-2021-33983HIGH7.8Buffer Overflow vulnerability in Dvidelabs flatcc v.0.6.0 allows local attacker to execute arbitrary code via the fltacc...
CVE-2021-33950HIGH7.5An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function...
CVE-2021-33926HIGH8.8An issue in Plone CMS v. 5.2.4, 5.2.3, 5.2.2, 5.2.1, 5.2.0, 5.1rc2, 5.1rc1, 5.1b4, 5.1b3, 5.1b2, 5.1a2, 5.1a1, 5.1.7, 5....

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now