2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-22732HIGH7.8Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could...
CVE-2021-22705HIGH7.8Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of ...
CVE-2021-22699HIGH7.5Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that co...
CVE-2021-20492HIGH8.2IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection...
CVE-2021-33506HIGH7.5jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This c...
CVE-2021-33194HIGH7.5golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop)...
CVE-2021-33038HIGH7.5An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a privat...
CVE-2021-32457HIGH7.8Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vuln...
CVE-2021-22543HIGH7.8An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and ...
CVE-2021-20209HIGH7.5A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are c...
CVE-2021-3320HIGH7.5Type Confusion in 802154 ACK Frames Handling. Zephyr versions >= v2.4.0 contain NULL Pointer Dereference (CWE-476). For ...
CVE-2021-23937HIGH7.5A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trig...
CVE-2021-21659HIGH8.1Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attack...
CVE-2021-21657HIGH8.8Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE...
CVE-2021-27823HIGH7.5An information disclosure vulnerability was discovered in /index.class.php (via port 8181) on NetWave System 1.0 which a...
CVE-2021-30195HIGH7.5CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
CVE-2021-30191HIGH7.5CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
CVE-2021-30186HIGH7.5CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
CVE-2021-20096HIGH8.1Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by t...
CVE-2021-33563HIGH7.5Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had...
CVE-2021-33525HIGH8.8EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in...
CVE-2021-30081HIGH8.8An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement ...
CVE-2021-29256HIGH8.8. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information d...
CVE-2021-33502HIGH7.5The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expressi...
CVE-2021-32629HIGH8.8Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermedi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now