2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32467HIGH7.5MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected...
CVE-2021-4166HIGH7.1vim is vulnerable to Out-of-bounds Read
CVE-2021-4162MEDIUM4.3archivy is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-45489HIGH7.5In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.
CVE-2021-45488HIGH7.5In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.
CVE-2021-45487HIGH7.5In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.
CVE-2021-45486LOW3.5In the IPv4 implementation in the Linux kernel before 5.12.4, net/ipv4/route.c has an information leak because the hash ...
CVE-2021-45485HIGH7.5In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of ...
CVE-2021-45484HIGH7.5In NetBSD through 9.2, the IPv6 fragment ID generation algorithm employs a weak cryptographic PRNG.
CVE-2021-45483MEDIUM6.5In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-3...
CVE-2021-45482MEDIUM6.5In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability t...
CVE-2021-45481MEDIUM6.5In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create...
CVE-2021-45480MEDIUM5.5An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function i...
CVE-2021-3977MEDIUM5.4invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-23574CRITICAL9.8All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn and the set functions. This is ...
CVE-2021-23490HIGH7.5The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkH...
CVE-2021-4072MEDIUM5.4elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-23772HIGH8.8This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The u...
CVE-2021-20876MEDIUM6.8Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlie...
CVE-2021-20875MEDIUM6.1Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier...
CVE-2021-20874HIGH7.5Incorrect permission assignment for critical resource vulnerability in GroupSession Free edition ver5.1.1 and earlier, G...
CVE-2021-20827HIGH7.5Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earli...
CVE-2021-20826HIGH7.6Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and ...
CVE-2021-45474MEDIUM6.1In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl pa...
CVE-2021-45473MEDIUM6.1In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now