2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-25143HIGH7.5A remote denial of service (dos) vulnerability was discovered in some Aruba Instant Access Point (IAP) products in versi...
CVE-2021-21727HIGH7.5A ZTE product has a DoS vulnerability. A remote attacker can amplify traffic by sending carefully constructed IPv6 packe...
CVE-2021-23358HIGH7.2The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code ...
CVE-2021-28937HIGH7.5The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) conta...
CVE-2021-28936HIGH7.5The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending ...
CVE-2021-29249HIGH7.5BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
CVE-2021-29266HIGH7.8An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_c...
CVE-2021-21374HIGH8.1Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, ...
CVE-2021-21372HIGH8.8Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, N...
CVE-2021-20206HIGH7.2An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying ...
CVE-2021-21389HIGH8.8BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2...
CVE-2021-21332HIGH8.2Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-29255HIGH7.5MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7...
CVE-2021-20271HIGH7A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who ca...
CVE-2021-22506HIGH7.5Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all vers...
CVE-2021-20682HIGH7.2baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS comma...
CVE-2021-28250HIGH7.8CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. W...
CVE-2021-28249HIGH8.8CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Obje...
CVE-2021-28248HIGH7.5CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts...
CVE-2021-28246HIGH7.8CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Obje...
CVE-2021-3119HIGH7.5Zetetic SQLCipher 4.x before 4.4.3 has a NULL pointer dereferencing issue related to sqlcipher_export in crypto.c and sq...
CVE-2021-29098HIGH7.8Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ...
CVE-2021-29097HIGH7.8Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcReader, ArcGIS Desktop, ArcGIS...
CVE-2021-27454HIGH7.8The software performs an operation at a privilege level higher than the minimum level required, which creates new weakne...
CVE-2021-27452HIGH7.8The software contains a hard-coded password that could allow an attacker to take control of the merging unit using these...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now