2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-26963HIGH7.2A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver...
CVE-2021-26962HIGH7.2A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver...
CVE-2021-26961HIGH8.8A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Plat...
CVE-2021-26960HIGH8.8A remote unauthenticated cross-site request forgery (csrf) vulnerability was discovered in Aruba AirWave Management Plat...
CVE-2021-28026HIGH7.8jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicou...
CVE-2021-28036HIGH7.5An issue was discovered in the quinn crate before 0.7.0 for Rust. It may have invalid memory access for certain versions...
CVE-2021-28030HIGH7.5An issue was discovered in the truetype crate before 0.30.1 for Rust. Attackers can read the contents of uninitialized m...
CVE-2021-28029HIGH7.5An issue was discovered in the toodee crate before 0.3.0 for Rust. The row-insertion feature allows attackers to read th...
CVE-2021-27963HIGH8.2SonLogger before 6.4.1 is affected by user creation with any user permissions profile (e.g., SuperAdmin). An anonymous u...
CVE-2021-3404HIGH7.8In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potential...
CVE-2021-3403HIGH7.8In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and...
CVE-2021-25337HIGH7.1Improper access control in clipboard service in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows untrusted ...
CVE-2021-23132HIGH7.5An issue was discovered in Joomla! 3.0.0 through 3.9.24. com_media allowed paths that are not intended for image uploads
CVE-2021-23131HIGH7.5An issue was discovered in Joomla! 3.2.0 through 3.9.24. Missing input validation within the template manager.
CVE-2021-22189HIGH7.2Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the ...
CVE-2021-27935HIGH7.5An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their...
CVE-2021-22884HIGH7.5Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “...
CVE-2021-22883HIGH7.5Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connecti...
CVE-2021-27927HIGH8.8In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0...
CVE-2021-22683HIGH7.8Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowi...
CVE-2021-22670HIGH7.8An uninitialized pointer may be exploited in Fatek FvDesigner Version 1.5.76 and prior while the application is processi...
CVE-2021-22666HIGH7.8Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a stack-based buffer overflow while project files are being p...
CVE-2021-22662HIGH7.8A use after free issue has been identified in Fatek FvDesigner Version 1.5.76 and prior in the way the application proce...
CVE-2021-22638HIGH7.8Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds read while processing project files, allowin...
CVE-2021-21979HIGH7.3In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r1...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now