2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28543 | HIGH | 7.5 | 1.5% | Mar 16, 2021 | Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some conf... |
| CVE-2021-21193 | HIGH | 8.8 | 9.9% | Mar 16, 2021 | Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2021-21192 | HIGH | 8.8 | 1.5% | Mar 16, 2021 | Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially explo... |
| CVE-2021-21191 | HIGH | 8.8 | 1.4% | Mar 16, 2021 | Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-27230 | HIGH | 8.8 | 2.8% | Mar 15, 2021 | ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leve... |
| CVE-2021-24029 | HIGH | 7.5 | 1.2% | Mar 15, 2021 | A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a cr... |
| CVE-2021-27948 | HIGH | 7.2 | 0.9% | Mar 15, 2021 | SQL Injection vulnerability in MyBB before 1.8.26 via User Groups. (issue 3 of 3). |
| CVE-2021-27947 | HIGH | 7.2 | 0.9% | Mar 15, 2021 | SQL Injection vulnerability in MyBB before 1.8.26 via the Copy Forum feature in Forum Management. (issue 2 of 3). |
| CVE-2021-27946 | HIGH | 8.8 | 4.2% | Mar 15, 2021 | SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3). |
| CVE-2021-27890 | HIGH | 8.8 | 10.6% | Mar 15, 2021 | SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files. |
| CVE-2021-22191 | HIGH | 8.8 | 3.6% | Mar 15, 2021 | Improper URL handling in Wireshark 3.4.0 to 3.4.3 and 3.2.0 to 3.2.11 could allow remote code execution via via packet i... |
| CVE-2021-27381 | HIGH | 7.8 | 0.9% | Mar 15, 2021 | A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < ... |
| CVE-2021-27380 | HIGH | 7.8 | 1.4% | Mar 15, 2021 | A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2021 (All Versions < ... |
| CVE-2021-25676 | HIGH | 7.5 | 1.3% | Mar 15, 2021 | A vulnerability has been identified in RUGGEDCOM RM1224 (V6.3), SCALANCE M-800 (V6.3), SCALANCE S615 (V6.3), SCALANCE SC... |
| CVE-2021-25672 | HIGH | 8.8 | 0.9% | Mar 15, 2021 | A vulnerability has been identified in Mendix Forgot Password Appstore module (All Versions < V3.2.1). The Forgot Passwo... |
| CVE-2021-25667 | HIGH | 8.8 | 0.9% | Mar 15, 2021 | A vulnerability has been identified in RUGGEDCOM RM1224 (All versions >= V4.3 and < V6.4), SCALANCE M-800 (All versions ... |
| CVE-2021-27893 | HIGH | 7 | 0.4% | Mar 15, 2021 | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. Connec... |
| CVE-2021-27892 | HIGH | 7.8 | 0.3% | Mar 15, 2021 | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affe... |
| CVE-2021-27891 | HIGH | 8.8 | 1.0% | Mar 15, 2021 | SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected. |
| CVE-2021-26923 | HIGH | 7.5 | 1.4% | Mar 15, 2021 | An issue was discovered in Argo CD before 1.8.4. Accessing the endpoint /api/version leaks internal information for the ... |
| CVE-2021-20179 | HIGH | 8.1 | 1.2% | Mar 15, 2021 | A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corres... |
| CVE-2021-27576 | HIGH | 7.5 | 2.8% | Mar 15, 2021 | If was found that the NetTest web service can be used to overload the bandwidth of a Apache OpenMeetings server. This is... |
| CVE-2021-28379 | HIGH | 8.8 | 6.0% | Mar 15, 2021 | web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow... |
| CVE-2021-28375 | HIGH | 7.8 | 0.3% | Mar 15, 2021 | An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not p... |
| CVE-2021-28374 | HIGH | 7.5 | 1.3% | Mar 15, 2021 | The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now