2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-29482HIGH7.5xz is a compression and decompression library focusing on the xz format completely written in Go. The function readUvari...
CVE-2021-25154HIGH7.5A remote escalation of privilege vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8...
CVE-2021-25153HIGH8.1A remote SQL injection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. A...
CVE-2021-25151HIGH8.8A remote insecure deserialization vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to ...
CVE-2021-25147HIGH8.1A remote authentication restriction bypass vulnerability was discovered in Aruba AirWave Management Platform version(s) ...
CVE-2021-22332HIGH7.5There is a pointer double free vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 an...
CVE-2021-22331HIGH7.5There is a JavaScript injection vulnerability in certain Huawei smartphones. A module does not verify some inputs suffic...
CVE-2021-22393HIGH7.5There is a denial of service vulnerability in some versions of CloudEngine 5800, CloudEngine 6800, CloudEngine 7800 and ...
CVE-2021-30169HIGH7.5The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s ...
CVE-2021-30166HIGH7.2The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers ...
CVE-2021-27648HIGH8.8Externally controlled reference to a resource in another sphere in quarantine functionality in Synology Antivirus Essent...
CVE-2021-31863HIGH7.5Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x b...
CVE-2021-3512HIGH8.8Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH ...
CVE-2021-29472HIGH8.8Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source d...
CVE-2021-29442HIGH7.5Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver...
CVE-2021-30638HIGH7.5Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files ins...
CVE-2021-29667HIGH7.8IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote ...
CVE-2021-3464HIGH7.8A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privil...
CVE-2021-28269HIGH8.8Soyal Technology 701Client 9.0.1 is vulnerable to Insecure permissions via client.exe binary with Authenticated Users gr...
CVE-2021-28271HIGH8.8Soyal Technologies SOYAL 701Server 9.0.1 suffers from an elevation of privileges vulnerability which can be used by an a...
CVE-2021-22664HIGH7.8CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds write, which may allow an attacker to execute arb...
CVE-2021-22660HIGH7.8CNCSoft-B Versions 1.0.0.3 and prior is vulnerable to an out-of-bounds read, which may allow an attacker to execute arbi...
CVE-2021-31826HIGH7.5Shibboleth Service Provider 3.x before 3.2.2 is prone to a NULL pointer dereference flaw involving the session recovery ...
CVE-2021-31671HIGH7.5pgsync before 0.6.7 is affected by Information Disclosure of sensitive information. Syncing the schema with the --schema...
CVE-2021-30165HIGH8.1The default administrator account & password of the EDIMAX wireless network camera is hard-coded. Remote attackers can d...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now