2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-21349HIGH8.6XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-21348HIGH7.5XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-21343HIGH7.5XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne...
CVE-2021-21341HIGH7.5XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnera...
CVE-2021-22314HIGH7.8There is a local privilege escalation vulnerability in some versions of ManageOne. A local authenticated attacker could ...
CVE-2021-22320HIGH7.5There is a denial of service vulnerability in Huawei products. A module cannot deal with specific messages correctly. At...
CVE-2021-22311HIGH7.2There is an improper permission assignment vulnerability in Huawei ManageOne product. Due to improper security hardening...
CVE-2021-26578HIGH7.5A potential security vulnerability has been identified in HPE Network Orchestrator (NetO) version(s): Prior to 2.5. The ...
CVE-2021-25265HIGH8.8A malicious website could execute code remotely in Sophos Connect Client before version 2.1.
CVE-2021-22309HIGH7.5There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Att...
CVE-2021-28148HIGH7.5One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before...
CVE-2021-27962HIGH7.1Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission...
CVE-2021-28956HIGH8.8The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execu...
CVE-2021-26070HIGH7.2Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protectio...
CVE-2021-23360HIGH8.8This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an atta...
CVE-2021-28961HIGH8.8applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenti...
CVE-2021-28954HIGH7.8In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository.
CVE-2021-28953HIGH7.8The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary b...
CVE-2021-28952HIGH7.8An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a bu...
CVE-2021-28117HIGH7.5libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially...
CVE-2021-21267HIGH7.5Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before ve...
CVE-2021-26992HIGH7.5Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a ...
CVE-2021-26991HIGH7.5Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow ...
CVE-2021-21387HIGH7.5Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0....
CVE-2021-28831HIGH7.5decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultan...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now