2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-26392HIGH7.8Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing ...
CVE-2021-26391HIGH7.8Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker w...
CVE-2021-26360HIGH7.8An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC...
CVE-2021-34579HIGH7.5In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of th...
CVE-2021-34568HIGH7.5In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co...
CVE-2021-34567HIGH8.2In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet co...
CVE-2021-39661HIGH7.8In _PMRLogicalOffsetToPhysicalOffset of the PowerVR kernel driver, there is a possible out of bounds write due to a miss...
CVE-2021-1050HIGH7.8In MMU_UnmapPages of the PowerVR kernel driver, there is a possible out of bounds write due to a missing bounds check. T...
CVE-2021-34055HIGH7.8jhead 3.06 is vulnerable to Buffer Overflow via exif.c in function Put16u.
CVE-2021-44862HIGH7.8Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information sto...
CVE-2021-36906HIGH8.8Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey Master plugin <= 7.3.6 ...
CVE-2021-45447HIGH7.5 Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.2 and 8.3.0.25 with the Data Lineage ...
CVE-2021-45446HIGH7.5A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not ca...
CVE-2021-37789HIGH8.1stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service...
CVE-2021-27784HIGH7.5The provided HCL Launch Container images contain non-unique HTTPS certificates and a database encryption key. The fix pr...
CVE-2021-40661HIGH7.5A remote, unauthenticated, directory traversal vulnerability was identified within the web interface used by IND780 Adva...
CVE-2021-36898HIGH7.2Auth. SQL Injection (SQLi) vulnerability in Quiz And Survey Master plugin <= 7.3.4 on WordPress.
CVE-2021-35387HIGH8.8Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
CVE-2021-38399HIGH7.5Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to relative path traversal, which may allow...
CVE-2021-4228HIGH7.4Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle (MitM) attacks even in the ...
CVE-2021-46850HIGH7.2myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An...
CVE-2021-46279HIGH8.8Session fixation and insufficient session expiration vulnerabilities allow an attacker to perfom session hijacking attac...
CVE-2021-44467HIGH7.5A broken access control vulnerability in the KillDupUsr_func function of spx_restservice allows an attacker to arbitrari...
CVE-2021-26733HIGH7.5A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to a...
CVE-2021-3305HIGH7.8Beijing Feishu Technology Co., Ltd Feishu v3.40.3 was discovered to contain an untrusted search path vulnerability.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now