2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-26684HIGH7.2A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-26683HIGH7.2A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-26681HIGH7.2A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio...
CVE-2021-22651HIGH7.8When loading a specially crafted file, Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10...
CVE-2021-20198HIGH8.1A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installat...
CVE-2021-20230HIGH7.5A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use ...
CVE-2021-20226HIGH7.8A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could caus...
CVE-2021-25630HIGH7.8"loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing a...
CVE-2021-3252HIGH7.5KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in...
CVE-2021-22649HIGH7.8Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering ve...
CVE-2021-22647HIGH7.8Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering ve...
CVE-2021-22645HIGH7.8Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering ve...
CVE-2021-22643HIGH7.8Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering ve...
CVE-2021-21157HIGH8.8Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially ...
CVE-2021-21156HIGH8.8Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap...
CVE-2021-21153HIGH8.8Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to poten...
CVE-2021-21152HIGH8.8Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially ...
CVE-2021-21149HIGH8.8Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to per...
CVE-2021-26724HIGH7.2OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and...
CVE-2021-26068HIGH8.8An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers t...
CVE-2021-3149HIGH7.2On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authen...
CVE-2021-26119HIGH7.5Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.
CVE-2021-27516HIGH7.5URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relati...
CVE-2021-27513HIGH8.8The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files becau...
CVE-2021-27509HIGH7.5In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now