2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-44860HIGH7.8An out-of-bounds read vulnerability exists when reading a TIF file using Open Design Alliance Drawings SDK before 2022.1...
CVE-2021-44859HIGH7.8An out-of-bounds read vulnerability exists when reading a TGA file using Open Design Alliance Drawings SDK before 2022.1...
CVE-2021-44423HIGH7.8An out-of-bounds read vulnerability exists when reading a BMP file using Open Design Alliance (ODA) Drawings Explorer be...
CVE-2021-44422HIGH7.8An Improper Input Validation Vulnerability exists when reading a BMP file using Open Design Alliance Drawings SDK before...
CVE-2021-38966MEDIUM5.4IBM Cloud Pak for Automation 21.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbi...
CVE-2021-38900MEDIUM6.5IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 could allow a pr...
CVE-2021-38893MEDIUM5.4IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0 and 21.0 are vulnerable t...
CVE-2021-45293MEDIUM5.5A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinar...
CVE-2021-45292MEDIUM5.5The gf_isom_hint_rtp_read function in GPAC 1.0.1 allows attackers to cause a denial of service (Invalid memory address d...
CVE-2021-45291MEDIUM5.5The gf_dump_setup function in GPAC 1.0.1 allows malicoius users to cause a denial of service (Invalid memory address der...
CVE-2021-45290HIGH7.5A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.
CVE-2021-45289MEDIUM5.5A vulnerability exists in GPAC 1.0.1 due to an omission of security-relevant Information, which could cause a Denial of ...
CVE-2021-44207HIGH8.1Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
CVE-2021-27453CRITICAL9.8Mesa Labs AmegaView Versions 3.0 uses default cookies that could be set to bypass authentication to the web application,...
CVE-2021-27451CRITICAL9.8Mesa Labs AmegaView Versions 3.0 and prior’s passcode is generated by an easily reversible algorithm, which may allow an...
CVE-2021-27449HIGH8.8Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute comman...
CVE-2021-27447CRITICAL9.8Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute ar...
CVE-2021-27445HIGH7.8Mesa Labs AmegaView Versions 3.0 and prior has insecure file permissions that could be exploited to escalate privileges ...
CVE-2021-45288MEDIUM5.5A Double Free vulnerability exists in filedump.c in GPAC 1.0.1, which could cause a Denail of Service via a crafted file...
CVE-2021-44877HIGH7.5Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Incorrect Access Control. The Systeam application is an ERP s...
CVE-2021-44876MEDIUM5.3Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system th...
CVE-2021-44875MEDIUM5.3Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam application is an ERP system th...
CVE-2021-44874HIGH8.8Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to Insecure design on report build via SQL query. The Systeam ap...
CVE-2021-43839HIGH7.5Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to...
CVE-2021-43587MEDIUM6.7Dell PowerPath Management Appliance, versions 3.2, 3.1, 3.0 P01, 3.0, and 2.6, use hard-coded cryptographic key. A local...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now