2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-45105MEDIUM5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursio...
CVE-2021-4131HIGH8.8livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4130HIGH8.8snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-41500HIGH7.5Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholm...
CVE-2021-41499HIGH7.5Buffer Overflow Vulnerability exists in ajaxsoundstudio.com n Pyo < 1.03 in the Server_debug function, which allows remo...
CVE-2021-41498HIGH7.5Buffer overflow in ajaxsoundstudio.com Pyo &lt and 1.03 in the Server_jack_init function. which allows attackers to cond...
CVE-2021-41497HIGH7.5Null pointer reference in CMS_Conservative_increment_obj in RaRe-Technologies bounter version 1.01 and 1.10, allows atta...
CVE-2021-41496MEDIUM5.5Buffer overflow in the array_from_pyobj function of fortranobject.c in NumPy < 1.19, which allows attackers to conduct a...
CVE-2021-41495MEDIUM5.3Null Pointer Dereference vulnerability exists in numpy.sort in NumPy &lt and 1.19 in the PyArray_DescrNew function due t...
CVE-2021-23814HIGH8.8This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficien...
CVE-2021-23803CRITICAL9.8This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the securit...
CVE-2021-23797CRITICAL9.8All versions of package http-server-node are vulnerable to Directory Traversal via use of --path-as-is.
CVE-2021-23450CRITICAL9.8All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
CVE-2021-43840MEDIUM6.5message_bus is a messaging bus for Ruby processes and web clients. In versions prior to 3.3.7 users who deployed message...
CVE-2021-43838HIGH7.5jsx-slack is a library for building JSON objects for Slack Block Kit surfaces from JSX. In versions prior to 4.5.1 users...
CVE-2021-34141MEDIUM5.3An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly ...
CVE-2021-33430MEDIUM5.3A Buffer Overflow vulnerability exists in NumPy 1.9.x in the PyArray_NewFromDescr_int function of ctors.c when specifyin...
CVE-2021-4011HIGH7.8A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t...
CVE-2021-4010HIGH7.8A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t...
CVE-2021-4009HIGH7.8A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t...
CVE-2021-4008HIGH7.8A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in t...
CVE-2021-40853HIGH7.2TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could ex...
CVE-2021-40852MEDIUM6.1TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to...
CVE-2021-40851HIGH7.5TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. Th...
CVE-2021-40850CRITICAL9.8TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now