2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-22703HIGH7.5A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/...
CVE-2021-22702HIGH7.5A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/...
CVE-2021-26296HIGH7.5In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, ...
CVE-2021-27405HIGH7.5A ReDoS (regular expression denial of service) flaw was found in the @progfay/scrapbox-parser package before 6.0.3 for N...
CVE-2021-26712HIGH7.5Incorrect access controls in res_srtp.c in Sangoma Asterisk 13.38.1, 16.16.0, 17.9.1, and 18.2.0 and Certified Asterisk ...
CVE-2021-26717HIGH7.5An issue was discovered in Sangoma Asterisk 16.x before 16.16.1, 17.x before 17.9.2, and 18.x before 18.2.1 and Certifie...
CVE-2021-27379HIGH7.8An issue was discovered in Xen through 4.11.x, allowing x86 Intel HVM guest OS users to achieve unintended read/write DM...
CVE-2021-23341HIGH7.5The package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc,...
CVE-2021-23340HIGH7.1This affects the package pimcore/pimcore before 6.8.8. A Local FIle Inclusion vulnerability exists in the downloadCsvAct...
CVE-2021-20443HIGH8.8IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library) from a source that is ou...
CVE-2021-20354HIGH7.5IBM WebSphere Application Server 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories. An attacker co...
CVE-2021-27138HIGH7.8The boot loader in Das U-Boot before 2021.04-rc2 mishandles use of unit addresses in a FIT.
CVE-2021-27097HIGH7.8The boot loader in Das U-Boot before 2021.04-rc2 mishandles a modified FIT.
CVE-2021-27374HIGH7.5VertiGIS WebOffice 10.7 SP1 before patch20210202 and 10.8 SP1 before patch20210207 allows attackers to achieve "Zugriff ...
CVE-2021-26720HIGH7.8avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-d...
CVE-2021-3396HIGH8.8OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through...
CVE-2021-27367HIGH7.5Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow D...
CVE-2021-26911HIGH7.4core/imap/MCIMAPSession.cpp in Canary Mail before 3.22 has Missing SSL Certificate Validation for IMAP in STARTTLS mode.
CVE-2021-1378HIGH7.5A vulnerability in the SSH service of the Cisco StarOS operating system could allow an unauthenticated, remote attacker ...
CVE-2021-1366HIGH7.8A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows c...
CVE-2021-27224HIGH7.5The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012e...
CVE-2021-25780HIGH7.2An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could...
CVE-2021-22174HIGH7.5Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture ...
CVE-2021-22173HIGH7.5Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted ca...
CVE-2021-22854HIGH7.5The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtai...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now