2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-40161HIGH7.8A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through PDFTron earli...
CVE-2021-40160HIGH7.8PDFTron prior to 9.0.7 version may be forced to read beyond allocated boundaries when parsing a maliciously crafted PDF ...
CVE-2021-4118HIGH7.8pytorch-lightning is vulnerable to Deserialization of Untrusted Data
CVE-2021-43854HIGH7.5NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2021-43849MEDIUM5.5cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both...
CVE-2021-3892Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2019-18198. Reason: This candidate is a reservation d...
CVE-2021-23175HIGH8.2NVIDIA GeForce Experience contains a vulnerability in user authorization, where GameStream does not correctly apply indi...
CVE-2021-44526CRITICAL9.8Zoho ManageEngine ServiceDesk Plus before 12003 allows authentication bypass in certain admin configurations.
CVE-2021-44600HIGH7.5The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injectio...
CVE-2021-44599HIGH7.5The id parameter from Online Enrollment Management System 1.0 system appears to be vulnerable to SQL injection attacks. ...
CVE-2021-44273HIGH7.4e2guardian v5.4.x <= v5.4.3r is affected by missing SSL certificate validation in the SSL MITM engine. In standalone mod...
CVE-2021-44548CRITICAL9.8An Improper Input Validation vulnerability in DataImportHandler of Apache Solr allows an attacker to provide a Windows U...
CVE-2021-4144HIGH8.8TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.
CVE-2021-45463HIGH7.8load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or ...
CVE-2021-45462HIGH7.5In Open5GS 2.4.0, a crafted packet from UE can crash SGW-U/UPF.
CVE-2021-20050HIGH7.5An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted management APIs being accessi...
CVE-2021-20049HIGH7.5A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker to perform SMA100 usern...
CVE-2021-4079HIGH8.8Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit he...
CVE-2021-4078HIGH8.8Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corrup...
CVE-2021-4068MEDIUM6.5Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cr...
CVE-2021-4067HIGH8.8Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potenti...
CVE-2021-4066HIGH8.8Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap ...
CVE-2021-4065HIGH8.8Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap ...
CVE-2021-4064HIGH8.8Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potenti...
CVE-2021-4063HIGH8.8Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now