2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29279 | HIGH | 7.8 | 1.0% | Apr 19, 2021 | There is a integer overflow in function filter_core/filter_props.c:gf_props_assign_value in GPAC 1.0.1. In which, the ar... |
| CVE-2021-31255 | HIGH | 7.8 | 1.5% | Apr 19, 2021 | Buffer overflow in the abst_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or e... |
| CVE-2021-31254 | HIGH | 7.8 | 1.5% | Apr 19, 2021 | Buffer overflow in the tenc_box_read function in MP4Box in GPAC 1.0.1 allows attackers to cause a denial of service or e... |
| CVE-2021-29457 | HIGH | 7.8 | 2.2% | Apr 19, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-20527 | HIGH | 7.2 | 1.1% | Apr 19, 2021 | IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as anot... |
| CVE-2021-27031 | HIGH | 7.8 | 1.4% | Apr 19, 2021 | A user may be tricked into opening a malicious FBX file which may exploit a use-after-free vulnerability in FBX's Review... |
| CVE-2021-27030 | HIGH | 7.8 | 59.6% | Apr 19, 2021 | A user may be tricked into opening a malicious FBX file which may exploit a Directory Traversal Remote Code Execution vu... |
| CVE-2021-27028 | HIGH | 7.8 | 2.3% | Apr 19, 2021 | A Memory Corruption Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to remote code execution throu... |
| CVE-2021-27027 | HIGH | 7.8 | 1.8% | Apr 19, 2021 | An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.0 and prior may lead to code execution through ma... |
| CVE-2021-21981 | HIGH | 7.8 | 0.2% | Apr 19, 2021 | VMware NSX-T contains a privilege escalation vulnerability due to an issue with RBAC (Role based access control) role as... |
| CVE-2021-20992 | HIGH | 7.5 | 1.4% | Apr 19, 2021 | In Fibaro Home Center 2 and Lite devices in all versions provide a web based management interface over unencrypted HTTP ... |
| CVE-2021-20991 | HIGH | 8.8 | 5.4% | Apr 19, 2021 | In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as... |
| CVE-2021-20990 | HIGH | 7.5 | 3.4% | Apr 19, 2021 | In Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older an internal management service is accessi... |
| CVE-2021-23380 | HIGH | 7.3 | 1.2% | Apr 18, 2021 | This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of t... |
| CVE-2021-3493 | HIGH | 7.8 | 44.0% | Apr 17, 2021 | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o... |
| CVE-2021-3492 | HIGH | 7.8 | 1.5% | Apr 17, 2021 | Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring ... |
| CVE-2021-27394 | HIGH | 8.8 | 0.8% | Apr 16, 2021 | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications... |
| CVE-2021-22539 | HIGH | 7.8 | 0.3% | Apr 16, 2021 | An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel a... |
| CVE-2021-26073 | HIGH | 7.7 | 0.9% | Apr 16, 2021 | Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Expr... |
| CVE-2021-21405 | HIGH | 7.5 | 1.0% | Apr 15, 2021 | Lotus is an Implementation of the Filecoin protocol written in Go. BLS signature validation in lotus uses blst library m... |
| CVE-2021-29430 | HIGH | 7.5 | 1.8% | Apr 15, 2021 | Sydent is a reference Matrix identity server. Sydent does not limit the size of requests it receives from HTTP clients. ... |
| CVE-2021-30245 | HIGH | 8.8 | 4.9% | Apr 15, 2021 | The project received a report that all versions of Apache OpenOffice through 4.1.8 can open non-http(s) hyperlinks. The ... |
| CVE-2021-31402 | HIGH | 7.5 | 1.2% | Apr 15, 2021 | The dio package 4.0.0 for Dart allows CRLF injection if the attacker controls the HTTP method string, a different vulner... |
| CVE-2021-29448 | HIGH | 8.8 | 0.7% | Apr 15, 2021 | Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the P... |
| CVE-2021-20288 | HIGH | 7.2 | 2.1% | Apr 15, 2021 | An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now