2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-28089HIGH7.5Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka T...
CVE-2021-28110HIGH7.5/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.
CVE-2021-25293HIGH7.5An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.
CVE-2021-25291HIGH7.5An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via ...
CVE-2021-25290HIGH7.5An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
CVE-2021-27928HIGH7.2A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a...
CVE-2021-27221HIGH8.1MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /expo...
CVE-2021-21384HIGH7.8shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to d...
CVE-2021-27358HIGH7.5The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of...
CVE-2021-1287HIGH7.2A vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDS...
CVE-2021-27656HIGH7.5A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-le...
CVE-2021-22665HIGH7.8Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a loc...
CVE-2021-28792HIGH7.8The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to e...
CVE-2021-28791HIGH7.8The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary co...
CVE-2021-28790HIGH7.8The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code...
CVE-2021-28789HIGH7.8The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbit...
CVE-2021-27306HIGH7.5An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users...
CVE-2021-26935HIGH7.5In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers S...
CVE-2021-24149HIGH8.8Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[...
CVE-2021-24146HIGH7.5Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not proper...
CVE-2021-24145HIGH7.2Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly chec...
CVE-2021-24144HIGH7.8Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability tha...
CVE-2021-24143HIGH8.8Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, ...
CVE-2021-24142HIGH7.2Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise ...
CVE-2021-24141HIGH7.2Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high pr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now