2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-28543HIGH7.5Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some conf...
CVE-2021-21193HIGH8.8Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap cor...
CVE-2021-21192HIGH8.8Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially explo...
CVE-2021-21191HIGH8.8Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap co...
CVE-2021-27230HIGH8.8ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leve...
CVE-2021-24029HIGH7.5A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a cr...
CVE-2021-27948HIGH7.2SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3).
CVE-2021-27947HIGH7.2SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3).
CVE-2021-27946HIGH8.8SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
CVE-2021-27890HIGH8.8SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
CVE-2021-22191HIGH8.8Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet i...
CVE-2021-27381HIGH7.8A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < ...
CVE-2021-27380HIGH7.8A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < ...
CVE-2021-25676HIGH7.5A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC...
CVE-2021-25672HIGH8.8A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Passwo...
CVE-2021-25667HIGH8.8A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions ...
CVE-2021-27893HIGH7SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. Connec...
CVE-2021-27892HIGH7.8SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affe...
CVE-2021-27891HIGH8.8SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected.
CVE-2021-26923HIGH7.5An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the ...
CVE-2021-20179HIGH8.1A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corres...
CVE-2021-27576HIGH7.5If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This is...
CVE-2021-28379HIGH8.8web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow...
CVE-2021-28375HIGH7.8An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not p...
CVE-2021-28374HIGH7.5The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now