2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-21552HIGH8.8Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. ...
CVE-2021-21549HIGH8.8Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged ...
CVE-2021-32634HIGH7.2Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserial...
CVE-2021-27811HIGH7.2A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execu...
CVE-2021-31475HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job S...
CVE-2021-31473HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.3.37...
CVE-2021-31440HIGH7This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An a...
CVE-2021-31439HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology Dis...
CVE-2021-32633HIGH8.8Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules...
CVE-2021-32032HIGH7.5In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the e...
CVE-2021-28798HIGH7.5A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, th...
CVE-2021-33477HIGH8.8rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improp...
CVE-2021-28906HIGH7.5In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In som...
CVE-2021-28905HIGH7.5In function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULL. But in some...
CVE-2021-28904HIGH7.5In function ext_get_plugin() in libyang <= v1.0.225, it doesn't check whether the value of revision is NULL. If revision...
CVE-2021-28903HIGH7.5A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem(). lyxml_parse_el...
CVE-2021-28902HIGH7.5In function read_yin_container() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. I...
CVE-2021-32630HIGH8.8Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before versio...
CVE-2021-29258HIGH7.5An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty META...
CVE-2021-28683HIGH7.5An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in T...
CVE-2021-28682HIGH7.5An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large ...
CVE-2021-27432HIGH7.5OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled re...
CVE-2021-29691HIGH7.5IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it u...
CVE-2021-29688HIGH7.5IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed techni...
CVE-2021-29686HIGH8.8IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they s...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now