2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22732 | HIGH | 7.8 | 0.3% | May 26, 2021 | Improper Privilege Management vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could... |
| CVE-2021-22705 | HIGH | 7.8 | 0.2% | May 26, 2021 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of ... |
| CVE-2021-22699 | HIGH | 7.5 | 1.0% | May 26, 2021 | Improper Input Validation vulnerability exists in Modicon M241/M251 logic controllers firmware prior to V5.1.9.1 that co... |
| CVE-2021-20492 | HIGH | 8.2 | 2.1% | May 26, 2021 | IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection... |
| CVE-2021-33506 | HIGH | 7.5 | 1.2% | May 26, 2021 | jitsi-meet-prosody in Jitsi Meet before 2.0.5963-1 does not ensure that restrict_room_creation is set by default. This c... |
| CVE-2021-33194 | HIGH | 7.5 | 7.5% | May 26, 2021 | golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop)... |
| CVE-2021-33038 | HIGH | 7.5 | 1.8% | May 26, 2021 | An issue was discovered in management/commands/hyperkitty_import.py in HyperKitty through 1.3.4. When importing a privat... |
| CVE-2021-32457 | HIGH | 7.8 | 0.4% | May 26, 2021 | Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vuln... |
| CVE-2021-22543 | HIGH | 7.8 | 0.7% | May 26, 2021 | An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and ... |
| CVE-2021-20209 | HIGH | 7.5 | 1.9% | May 25, 2021 | A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are c... |
| CVE-2021-3320 | HIGH | 7.5 | 0.8% | May 25, 2021 | Type Confusion in 802154 ACK Frames Handling. Zephyr versions >= v2.4.0 contain NULL Pointer Dereference (CWE-476). For ... |
| CVE-2021-23937 | HIGH | 7.5 | 4.3% | May 25, 2021 | A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trig... |
| CVE-2021-21659 | HIGH | 8.1 | 66.8% | May 25, 2021 | Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attack... |
| CVE-2021-21657 | HIGH | 8.8 | 1.6% | May 25, 2021 | Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE... |
| CVE-2021-27823 | HIGH | 7.5 | 1.1% | May 25, 2021 | An information disclosure vulnerability was discovered in /index.class.php (via port 8181) on NetWave System 1.0 which a... |
| CVE-2021-30195 | HIGH | 7.5 | 7.2% | May 25, 2021 | CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. |
| CVE-2021-30191 | HIGH | 7.5 | 1.0% | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input. |
| CVE-2021-30186 | HIGH | 7.5 | 7.4% | May 25, 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow. |
| CVE-2021-20096 | HIGH | 8.1 | 0.6% | May 25, 2021 | Cross-site request forgery in OpenOversight 0.6.4 allows a remote attacker to perform sensitive application actions by t... |
| CVE-2021-33563 | HIGH | 7.5 | 0.8% | May 24, 2021 | Koel before 5.1.4 lacks login throttling, lacks a password strength policy, and shows whether a failed login attempt had... |
| CVE-2021-33525 | HIGH | 8.8 | 7.7% | May 24, 2021 | EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in... |
| CVE-2021-30081 | HIGH | 8.8 | 1.0% | May 24, 2021 | An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement ... |
| CVE-2021-29256 | HIGH | 8.8 | 3.0% | May 24, 2021 | . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information d... |
| CVE-2021-33502 | HIGH | 7.5 | 1.7% | May 24, 2021 | The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expressi... |
| CVE-2021-32629 | HIGH | 8.8 | 0.5% | May 24, 2021 | Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermedi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now