2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3154 | HIGH | 7.5 | 1.2% | May 4, 2021 | An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords v... |
| CVE-2021-22547 | HIGH | 7.8 | 0.2% | May 4, 2021 | In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in m... |
| CVE-2021-29240 | HIGH | 7.8 | 0.9% | May 4, 2021 | The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before insta... |
| CVE-2021-23343 | HIGH | 7.5 | 2.2% | May 4, 2021 | All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, spl... |
| CVE-2021-31164 | HIGH | 7.5 | 2.3% | May 4, 2021 | Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. |
| CVE-2021-29242 | HIGH | 7.3 | 1.1% | May 3, 2021 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication p... |
| CVE-2021-29241 | HIGH | 7.5 | 1.4% | May 3, 2021 | CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS). |
| CVE-2021-29239 | HIGH | 7.8 | 0.2% | May 3, 2021 | CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries wit... |
| CVE-2021-29238 | HIGH | 8.8 | 0.5% | May 3, 2021 | CODESYS Automation Server before 1.16.0 allows cross-site request forgery (CSRF). |
| CVE-2021-25631 | HIGH | 8.8 | 4.2% | May 3, 2021 | In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist... |
| CVE-2021-31996 | HIGH | 7.5 | 1.0% | May 3, 2021 | An issue was discovered in the algorithmica crate through 2021-03-07 for Rust. There is a double free in merge_sort::mer... |
| CVE-2021-31933 | HIGH | 7.2 | 13.9% | Apr 30, 2021 | A remote code execution vulnerability exists in Chamilo through 1.11.14 due to improper input sanitization of a paramete... |
| CVE-2021-21540 | HIGH | 8.1 | 1.2% | Apr 30, 2021 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a stack-based overflow vulnerability. A remote authenticated attack... |
| CVE-2021-21539 | HIGH | 7.1 | 0.6% | Apr 30, 2021 | Dell EMC iDRAC9 versions prior to 4.40.00.00 contain a Time-of-check Time-of-use (TOCTOU) race condition vulnerability. ... |
| CVE-2021-21531 | HIGH | 7.8 | 0.7% | Apr 30, 2021 | Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass Vulnerability. A local authenticat... |
| CVE-2021-21530 | HIGH | 8.8 | 0.9% | Apr 30, 2021 | Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authent... |
| CVE-2021-21233 | HIGH | 8.8 | 1.3% | Apr 30, 2021 | Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially... |
| CVE-2021-21232 | HIGH | 8.8 | 1.1% | Apr 30, 2021 | Use after free in Dev Tools in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap... |
| CVE-2021-21231 | HIGH | 8.8 | 1.1% | Apr 30, 2021 | Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially explo... |
| CVE-2021-21230 | HIGH | 8.8 | 1.6% | Apr 30, 2021 | Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corrup... |
| CVE-2021-21227 | HIGH | 8.8 | 1.2% | Apr 30, 2021 | Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially explo... |
| CVE-2021-29464 | HIGH | 7.8 | 1.5% | Apr 30, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-29486 | HIGH | 7.5 | 2.0% | Apr 30, 2021 | cumulative-distribution-function is an open source npm library used which calculates statistical cumulative distribution... |
| CVE-2021-21535 | HIGH | 7.8 | 0.2% | Apr 30, 2021 | Dell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local... |
| CVE-2021-26807 | HIGH | 7.8 | 0.5% | Apr 30, 2021 | GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PAT... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now