2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-20442HIGH7.5IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for i...
CVE-2021-20233HIGH8.2A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calc...
CVE-2021-20076HIGH8.8Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an ...
CVE-2021-26813HIGH7.5markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacke...
CVE-2021-25315HIGH7.8CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows...
CVE-2021-27923HIGH7.5Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co...
CVE-2021-27922HIGH7.5Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co...
CVE-2021-27921HIGH7.5Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co...
CVE-2021-22863HIGH8.1An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authent...
CVE-2021-27065HIGH7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26858HIGH7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26857HIGH7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-27885HIGH8.8usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
CVE-2021-25330HIGH7.5Calling of non-existent provider in MobileWips application prior to SMR Feb-2021 Release 1 allows unauthorized actions i...
CVE-2021-25306HIGH7.5A buffer overflow vulnerability in the AT command interface of Gigaset DX600A v41.00-175 devices allows remote attackers...
CVE-2021-27878HIGH8.8An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc...
CVE-2021-27876HIGH8.1An issue was discovered in Veritas Backup Exec before 21.2. The communication between a client and an Agent requires suc...
CVE-2021-26704HIGH8.8EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/too...
CVE-2021-21517HIGH7.2SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML pa...
CVE-2021-25829HIGH7.5An improper binary stream data handling issue was found in the [core] module of ONLYOFFICE DocumentServer v4.0.0-9-v5.6....
CVE-2021-25329HIGH7The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5...
CVE-2021-25122HIGH7.5When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0...
CVE-2021-27803HIGH7.5A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision ...
CVE-2021-27799HIGH7.5ean_leading_zeroes in backend/upcean.c in Zint Barcode Generator 2.9.1 has a stack-based buffer overflow that is reachab...
CVE-2021-26567HIGH7.8Stack-based buffer overflow vulnerability in frontend/main.c in faad2 before 2.2.7.1 allow local attackers to execute ar...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now