2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28089 | HIGH | 7.5 | 1.7% | Mar 19, 2021 | Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka T... |
| CVE-2021-28110 | HIGH | 7.5 | 1.0% | Mar 19, 2021 | /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser. |
| CVE-2021-25293 | HIGH | 7.5 | 1.6% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c. |
| CVE-2021-25291 | HIGH | 7.5 | 1.4% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via ... |
| CVE-2021-25290 | HIGH | 7.5 | 2.4% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size. |
| CVE-2021-27928 | HIGH | 7.2 | 38.4% | Mar 19, 2021 | A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a... |
| CVE-2021-27221 | HIGH | 8.1 | 4.5% | Mar 19, 2021 | MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /expo... |
| CVE-2021-21384 | HIGH | 7.8 | 0.6% | Mar 19, 2021 | shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to d... |
| CVE-2021-27358 | HIGH | 7.5 | 83.0% | Mar 18, 2021 | The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of... |
| CVE-2021-1287 | HIGH | 7.2 | 2.2% | Mar 18, 2021 | A vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDS... |
| CVE-2021-27656 | HIGH | 7.5 | 1.2% | Mar 18, 2021 | A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-le... |
| CVE-2021-22665 | HIGH | 7.8 | 0.4% | Mar 18, 2021 | Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a loc... |
| CVE-2021-28792 | HIGH | 7.8 | 1.7% | Mar 18, 2021 | The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to e... |
| CVE-2021-28791 | HIGH | 7.8 | 1.6% | Mar 18, 2021 | The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary co... |
| CVE-2021-28790 | HIGH | 7.8 | 1.7% | Mar 18, 2021 | The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code... |
| CVE-2021-28789 | HIGH | 7.8 | 1.7% | Mar 18, 2021 | The unofficial apple/swift-format extension before 1.1.2 for Visual Studio Code allows remote attackers to execute arbit... |
| CVE-2021-27306 | HIGH | 7.5 | 1.8% | Mar 18, 2021 | An improper access control vulnerability in the JWT plugin in Kong Gateway prior to 2.3.2.0 allows unauthenticated users... |
| CVE-2021-26935 | HIGH | 7.5 | 2.3% | Mar 18, 2021 | In WoWonder < 3.1, remote attackers can gain access to the database by exploiting a requests.php?f=search-my-followers S... |
| CVE-2021-24149 | HIGH | 8.8 | 1.5% | Mar 18, 2021 | Unvalidated input in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.6, did not sanitise the mec[... |
| CVE-2021-24146 | HIGH | 7.5 | 31.0% | Mar 18, 2021 | Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not proper... |
| CVE-2021-24145 | HIGH | 7.2 | 88.2% | Mar 18, 2021 | Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly chec... |
| CVE-2021-24144 | HIGH | 7.8 | 1.2% | Mar 18, 2021 | Unvalidated input in the Contact Form 7 Database Addon plugin, versions before 1.2.5.6, was prone to a vulnerability tha... |
| CVE-2021-24143 | HIGH | 8.8 | 1.3% | Mar 18, 2021 | Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, ... |
| CVE-2021-24142 | HIGH | 7.2 | 1.2% | Mar 18, 2021 | Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise ... |
| CVE-2021-24141 | HIGH | 7.2 | 1.2% | Mar 18, 2021 | Unvaludated input in the Advanced Database Cleaner plugin, versions before 3.0.2, lead to SQL injection allowing high pr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now