2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20442 | HIGH | 7.5 | 1.0% | Mar 3, 2021 | IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for i... |
| CVE-2021-20233 | HIGH | 8.2 | 0.6% | Mar 3, 2021 | A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calc... |
| CVE-2021-20076 | HIGH | 8.8 | 2.0% | Mar 3, 2021 | Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an ... |
| CVE-2021-26813 | HIGH | 7.5 | 2.4% | Mar 3, 2021 | markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacke... |
| CVE-2021-25315 | HIGH | 7.8 | 2.3% | Mar 3, 2021 | CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows... |
| CVE-2021-27923 | HIGH | 7.5 | 3.1% | Mar 3, 2021 | Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co... |
| CVE-2021-27922 | HIGH | 7.5 | 4.9% | Mar 3, 2021 | Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co... |
| CVE-2021-27921 | HIGH | 7.5 | 3.2% | Mar 3, 2021 | Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co... |
| CVE-2021-22863 | HIGH | 8.1 | 1.0% | Mar 3, 2021 | An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authent... |
| CVE-2021-27065 | HIGH | 7.8 | 99.9% | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26858 | HIGH | 7.8 | 89.5% | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-26857 | HIGH | 7.8 | 94.0% | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-27885 | HIGH | 8.8 | 3.2% | Mar 2, 2021 | usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism. |
| CVE-2021-25330 | HIGH | 7.5 | 0.4% | Mar 2, 2021 | Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions i... |
| CVE-2021-25306 | HIGH | 7.5 | 1.5% | Mar 2, 2021 | A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers... |
| CVE-2021-27878 | HIGH | 8.8 | 24.0% | Mar 1, 2021 | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc... |
| CVE-2021-27876 | HIGH | 8.1 | 13.4% | Mar 1, 2021 | An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc... |
| CVE-2021-26704 | HIGH | 8.8 | 3.1% | Mar 1, 2021 | EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/too... |
| CVE-2021-21517 | HIGH | 7.2 | 1.4% | Mar 1, 2021 | SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML pa... |
| CVE-2021-25829 | HIGH | 7.5 | 7.4% | Mar 1, 2021 | An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6.... |
| CVE-2021-25329 | HIGH | 7 | 9.5% | Mar 1, 2021 | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5... |
| CVE-2021-25122 | HIGH | 7.5 | 18.1% | Mar 1, 2021 | When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0... |
| CVE-2021-27803 | HIGH | 7.5 | 1.2% | Feb 26, 2021 | A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision ... |
| CVE-2021-27799 | HIGH | 7.5 | 2.4% | Feb 26, 2021 | ean_leading_zeroes in backend/upcean.c in Zint Barcode Generator 2.9.1 has a stack-based buffer overflow that is reachab... |
| CVE-2021-26567 | HIGH | 7.8 | 1.1% | Feb 26, 2021 | Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute ar... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now