2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-1474HIGH8.6Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could all...
CVE-2021-1386HIGH7.8A vulnerability in the dynamic link library (DLL) loading mechanism in Cisco Advanced Malware Protection (AMP) for Endpo...
CVE-2021-1362HIGH8.8A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager S...
CVE-2021-1309HIGH8.8Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se...
CVE-2021-1308HIGH7.4Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se...
CVE-2021-1251HIGH7.4Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Se...
CVE-2021-1137HIGH7.8Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb...
CVE-2021-29641HIGH8.8Directus 8 before 8.8.2 allows remote authenticated users to execute arbitrary code because file-upload permissions incl...
CVE-2021-26758HIGH8.8Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root term...
CVE-2021-30123HIGH8.8FFmpeg <=4.3 contains a buffer overflow vulnerability in libavcodec through a crafted file that may lead to remote code ...
CVE-2021-29627HIGH7.8In FreeBSD 13.0-STABLE before n245050, 12.2-STABLE before r369525, 13.0-RC4 before p0, and 12.2-RELEASE before p6, liste...
CVE-2021-28927HIGH7.8The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platfor...
CVE-2021-30185HIGH7.5CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link.
CVE-2021-30184HIGH7.8GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is relate...
CVE-2021-20692HIGH7.1Directory traversal vulnerability in Archive collectively operation utility Ver.2.10.1.0 and earlier allows an attacker ...
CVE-2021-20687HIGH8.8Cross-site request forgery (CSRF) vulnerability in Kagemai 0.8.8 allows remote attackers to hijack the authentication of...
CVE-2021-1892HIGH7.8Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Comput...
CVE-2021-30147HIGH8.8DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
CVE-2021-27900HIGH8.1The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several...
CVE-2021-27899HIGH7.4The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validati...
CVE-2021-22158HIGH7.2The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) i...
CVE-2021-21404HIGH7.5Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv...
CVE-2021-21423HIGH8.1`projen` is a project generation tool that synthesizes project configuration files such as `package.json`, `tsconfig.jso...
CVE-2021-24027HIGH7.5A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may ha...
CVE-2021-20334HIGH7.8A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now