2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-3902CRITICAL9.8An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Re...
CVE-2021-3838CRITICAL9.8DomPDF before version 2.0.0 is vulnerable to PHAR deserialization due to a lack of checking on the protocol before passi...
CVE-2021-35473CRITICAL9.1An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e...
CVE-2021-4449CRITICAL9.8The ZoomSounds plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '...
CVE-2021-4448CRITICAL9.8The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including...
CVE-2021-4443CRITICAL9.8The WordPress Mega Menu plugin for WordPress is vulnerable to Arbitrary File Creation in versions up to, and including, ...
CVE-2021-27915CRITICAL9Prior to the patched version, there is an XSS vulnerability in the description fields within the Mautic application whic...
CVE-2021-38132CRITICAL9.8Possible External Service Interaction attack in eDirectory has been discovered in OpenText™ eDirectory. This impact al...
CVE-2021-22533CRITICAL9.1Possible Insertion of Sensitive Information into Log File Vulnerability in eDirectory has been discovered in OpenText™ ...
CVE-2021-22530CRITICAL9.9A vulnerability identified in NetIQ Advance Authentication that doesn't enforce account lockout when brute force attack ...
CVE-2021-47548CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ethernet: hisilicon: hns: hns_dsaf_misc: fix a poss...
CVE-2021-47478CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs ...
CVE-2021-47378CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: destroy cm id before destroy qp to avoid...
CVE-2021-47348CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruptio...
CVE-2021-47232CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: can: j1939: fix Use-after-Free, hold skb ref while ...
CVE-2021-27312CRITICAL9.4Server Side Request Forgery (SSRF) vulnerability in Gleez Cms 1.2.0, allows remote attackers to execute arbitrary code a...
CVE-2021-47137CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a...
CVE-2021-47157CRITICAL9.8The Kossy module before 0.60 for Perl allows JSON hijacking because of X-Requested-With mishandling.
CVE-2021-47155CRITICAL9.1The Net::IPV4Addr module 0.10 for Perl does not properly consider extraneous zero characters in an IP address string, wh...
CVE-2021-4436CRITICAL9.8The 3DPrint Lite WordPress plugin before 1.9.1.5 does not have any authorisation and does not check the uploaded file in...
CVE-2021-21575CRITICAL9.8 Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
CVE-2021-42147CRITICAL9.1Buffer over-read vulnerability in the dtls_sha256_update function in Contiki-NG tinyDTLS through master branch 53a0d97 a...
CVE-2021-42144CRITICAL9.8Buffer over-read vulnerability in Contiki-NG tinyDTLS through master branch 53a0d97 allows attackers obtain sensitive in...
CVE-2021-42143CRITICAL9.1An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. An infinite loop bug exists during the han...
CVE-2021-42142CRITICAL9.8An issue was discovered in Contiki-NG tinyDTLS through master branch 53a0d97. DTLS servers mishandle the early use of a ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now