2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26684 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-26683 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-26681 | HIGH | 7.2 | 2.5% | Feb 23, 2021 | A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio... |
| CVE-2021-22651 | HIGH | 7.8 | 2.6% | Feb 23, 2021 | When loading a specially crafted file, Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10... |
| CVE-2021-20198 | HIGH | 8.1 | 1.8% | Feb 23, 2021 | A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installat... |
| CVE-2021-20230 | HIGH | 7.5 | 1.2% | Feb 23, 2021 | A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use ... |
| CVE-2021-20226 | HIGH | 7.8 | 0.4% | Feb 23, 2021 | A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could caus... |
| CVE-2021-25630 | HIGH | 7.8 | 0.3% | Feb 23, 2021 | "loolforkit" is a privileged program that is supposed to be run by a special, non-privileged "lool" user. Before doing a... |
| CVE-2021-3252 | HIGH | 7.5 | 2.6% | Feb 23, 2021 | KACO New Energy XP100U Up to XP-JAVA 2.0 is affected by incorrect access control. Credentials will always be returned in... |
| CVE-2021-22649 | HIGH | 7.8 | 2.2% | Feb 23, 2021 | Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering ve... |
| CVE-2021-22647 | HIGH | 7.8 | 2.1% | Feb 23, 2021 | Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering ve... |
| CVE-2021-22645 | HIGH | 7.8 | 1.5% | Feb 23, 2021 | Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering ve... |
| CVE-2021-22643 | HIGH | 7.8 | 2.1% | Feb 23, 2021 | Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering ve... |
| CVE-2021-21157 | HIGH | 8.8 | 9.5% | Feb 22, 2021 | Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially ... |
| CVE-2021-21156 | HIGH | 8.8 | 2.7% | Feb 22, 2021 | Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap... |
| CVE-2021-21153 | HIGH | 8.8 | 1.3% | Feb 22, 2021 | Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to poten... |
| CVE-2021-21152 | HIGH | 8.8 | 1.3% | Feb 22, 2021 | Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially ... |
| CVE-2021-21149 | HIGH | 8.8 | 1.5% | Feb 22, 2021 | Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to per... |
| CVE-2021-26724 | HIGH | 7.2 | 3.1% | Feb 22, 2021 | OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and... |
| CVE-2021-26068 | HIGH | 8.8 | 2.7% | Feb 22, 2021 | An endpoint in Atlassian Jira Server for Slack plugin from version 0.0.3 before version 2.0.15 allows remote attackers t... |
| CVE-2021-3149 | HIGH | 7.2 | 4.4% | Feb 22, 2021 | On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authen... |
| CVE-2021-26119 | HIGH | 7.5 | 9.4% | Feb 22, 2021 | Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode. |
| CVE-2021-27516 | HIGH | 7.5 | 2.5% | Feb 22, 2021 | URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relati... |
| CVE-2021-27513 | HIGH | 8.8 | 28.4% | Feb 22, 2021 | The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files becau... |
| CVE-2021-27509 | HIGH | 7.5 | 1.0% | Feb 19, 2021 | In Visualware MyConnection Server before 11.0b build 5382, each published report is not associated with its own access c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now