2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-26474HIGH8.8Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products o...
CVE-2021-33571HIGH7.5In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_...
CVE-2021-32674HIGH8.8Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefou...
CVE-2021-34280HIGH7.8Polaris Office v9.103.83.44230 is affected by a Uninitialized Pointer Vulnerability in PolarisOffice.exe and EngineDLL.d...
CVE-2021-33176HIGH7.5VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memor...
CVE-2021-33175HIGH7.5EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consum...
CVE-2021-22214HIGH8.6When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE...
CVE-2021-22550HIGH7.8An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave....
CVE-2021-22549HIGH7.8An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended t...
CVE-2021-22548HIGH7.8An attacker can change the pointer to untrusted memory to point to trusted memory region which causes copying trusted me...
CVE-2021-22212HIGH7.4ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters...
CVE-2021-23169HIGH8.8A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker co...
CVE-2021-22116HIGH7.5RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in...
CVE-2021-33560HIGH7.5Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to addres...
CVE-2021-23392HIGH7.5The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir...
CVE-2021-28811HIGH7.2If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has...
CVE-2021-28810HIGH7.5If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without prope...
CVE-2021-3277HIGH7.2Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rena...
CVE-2021-29504HIGH7.4WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI ve...
CVE-2021-23391HIGH7.1This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary f...
CVE-2021-20259HIGH7.8A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authent...
CVE-2021-30543HIGH8.8Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a...
CVE-2021-30542HIGH8.8Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a...
CVE-2021-30536HIGH8.1Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack c...
CVE-2021-30535HIGH8.8Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corrupti...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now