2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45951CRITICAL9.8Dnsmasq 2.86 has a heap-based buffer overflow in check_bad_address (called from check_for_bogus_wildcard and FuzzCheckFo...
CVE-2021-45950MEDIUM6.5LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOC...
CVE-2021-45949MEDIUM5.5Ghostscript GhostPDL 9.50 through 9.54.0 has a heap-based buffer overflow in sampled_data_finish (called from sampled_da...
CVE-2021-45948MEDIUM5.5Open Asset Import Library (aka assimp) 5.1.0 and 5.1.1 has a heap-based buffer overflow in _m3d_safestr (called from m3d...
CVE-2021-45947MEDIUM5.5Wasm3 0.5.0 has an out-of-bounds write in Runtime_Release (called from EvaluateExpression and InitDataSegments).
CVE-2021-45946MEDIUM5.5Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from Compile_LoopOrBlock and CompileBlockStatements).
CVE-2021-45945Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-45944MEDIUM5.5Ghostscript GhostPDL 9.50 through 9.53.3 has a use-after-free in sampled_data_sample (called from sampled_data_continue ...
CVE-2021-45929MEDIUM5.5Wasm3 0.5.0 has an out-of-bounds write in CompileBlock (called from CompileElseBlock and Compile_If).
CVE-2021-4193MEDIUM5.5vim is vulnerable to Out-of-bounds Read
CVE-2021-4192HIGH7.8vim is vulnerable to Use After Free
CVE-2021-4190HIGH7.5Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture fi...
CVE-2021-4186HIGH7.5Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted cap...
CVE-2021-4185HIGH7.5Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injectio...
CVE-2021-4184HIGH7.5Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet...
CVE-2021-4183MEDIUM5.5Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
CVE-2021-4182HIGH7.5Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or ...
CVE-2021-4181HIGH7.5Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection...
CVE-2021-45732HIGH8.8Netgear Nighthawk R6700 version 1.0.4.120 makes use of a hardcoded credential. It does not appear that normal users are ...
CVE-2021-45077HIGH7.5Netgear Nighthawk R6700 version 1.0.4.120 stores sensitive information in plaintext. All usernames and passwords for the...
CVE-2021-44466HIGH7.3Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software ...
CVE-2021-23147MEDIUM6.8Netgear Nighthawk R6700 version 1.0.4.120 does not have sufficient protections for the UART console. A malicious actor w...
CVE-2021-20175HIGH7.5Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the SOAP interface. By defaul...
CVE-2021-20174HIGH7.5Netgear Nighthawk R6700 version 1.0.4.120 does not utilize secure communication methods to the web interface. By default...
CVE-2021-20173HIGH8.8Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the devi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now