2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-27406HIGH8.8An attacker can take leverage on PerFact OpenVPN-Client versions 1.4.1.0 and prior to send the config command from any a...
CVE-2021-22685HIGH7.5An attacker may be able to use minify route with a relative path to view any file on the Cassia Networks Access Controll...
CVE-2021-0699HIGH7.8In HTBLogKM of TBD, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca...
CVE-2021-20030HIGH7.5SonicWall GMS is vulnerable to file path manipulation resulting that an unauthenticated attacker can gain access to web ...
CVE-2021-36369HIGH7.5An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication me...
CVE-2021-0951HIGH7.8In DevmemIntHeapAcquire of TBD, there is a possible arbitrary code execution due to an integer overflow. This could lead...
CVE-2021-0696HIGH7In dllist_remove_node of TBD, there is a possible use after free bug due to a race condition. This could lead to local e...
CVE-2021-36913HIGH7.5Unauthenticated Options Change and Content Injection vulnerability in Qube One Redirection for Contact Form 7 plugin <= ...
CVE-2021-44171HIGH8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version...
CVE-2021-40166HIGH7.8A maliciously crafted PNG file in Autodesk Image Processing component may be used to attempt to free an object that has ...
CVE-2021-40165HIGH7.8A maliciously crafted TIFF, PICT, TGA, or RLC file in Autodesk Image Processing component may be used to write beyond th...
CVE-2021-40164HIGH7.8A heap-based buffer overflow could occur while parsing TIFF, PICT, TGA, or RLC files. This vulnerability may be exploite...
CVE-2021-40163HIGH7.8A Memory Corruption vulnerability may lead to code execution through maliciously crafted DLL files through Autodesk Imag...
CVE-2021-40162HIGH7.8A maliciously crafted TIF, PICT, TGA, or RLC files in Autodesk Image Processing component may be forced to read beyond a...
CVE-2021-40556HIGH8.8A stack overflow vulnerability exists in the httpd service in ASUS RT-AX56U Router Version 3.0.0.4.386.44266. This vulne...
CVE-2021-33354HIGH8.1Directory Traversal vulnerability in htmly before 2.8.1 allows remote attackers to perform arbitrary file deletions via ...
CVE-2021-36854HIGH8.8Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress.
CVE-2021-45788HIGH8.8Time-based SQL Injection vulnerabilities were found in Metersphere v1.15.4 via the "orders" parameter.
CVE-2021-24890HIGH8.8The Scripts Organizer WordPress plugin before 3.0 does not have capability and CSRF checks in the saveScript AJAX action...
CVE-2021-41803HIGH7.1HashiCorp Consul 1.8.1 up to 1.11.8, 1.12.4, and 1.13.1 do not properly validate the node or segment names prior to inte...
CVE-2021-46836HIGH7.5Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of th...
CVE-2021-40024HIGH7.5Implementation of the WLAN module interfaces has the information disclosure vulnerability. Successful exploitation of th...
CVE-2021-40023HIGH7.5Configuration defects in the secure OS module. Successful exploitation of this vulnerability will affect confidentiality...
CVE-2021-38924HIGH7.5IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 could allow a remote attacker to obtain sensitive information when a det...
CVE-2021-0943HIGH7.8In MMU_MapPages of TBD, there is a possible out of bounds write due to improper input validation. This could lead to loc...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now