2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0109 | HIGH | 7.8 | 0.2% | Feb 17, 2021 | Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authent... |
| CVE-2021-22553 | HIGH | 7.5 | 0.4% | Feb 17, 2021 | Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not ... |
| CVE-2021-22858 | HIGH | 8.8 | 1.2% | Feb 17, 2021 | Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrar... |
| CVE-2021-22857 | HIGH | 7.5 | 1.8% | Feb 17, 2021 | The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to dow... |
| CVE-2021-22856 | HIGH | 7.5 | 1.4% | Feb 17, 2021 | The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into... |
| CVE-2021-23885 | HIGH | 8.8 | 1.1% | Feb 17, 2021 | Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain eleva... |
| CVE-2021-20655 | HIGH | 7.2 | 4.0% | Feb 17, 2021 | FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary ... |
| CVE-2021-26934 | HIGH | 7.8 | 0.3% | Feb 17, 2021 | An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) ... |
| CVE-2021-26930 | HIGH | 7.8 | 0.3% | Feb 17, 2021 | An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend,... |
| CVE-2021-27102 | HIGH | 7.8 | 3.7% | Feb 16, 2021 | Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version i... |
| CVE-2021-20075 | HIGH | 7.8 | 0.2% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd. |
| CVE-2021-20074 | HIGH | 8.8 | 1.2% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and ... |
| CVE-2021-20073 | HIGH | 8.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries. |
| CVE-2021-20072 | HIGH | 7.2 | 1.4% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an ... |
| CVE-2021-21316 | HIGH | 7.8 | 1.0% | Feb 16, 2021 | less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10.,... |
| CVE-2021-23840 | HIGH | 7.5 | 50.7% | Feb 16, 2021 | Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases... |
| CVE-2021-21315 | HIGH | 7.8 | 90.2% | Feb 16, 2021 | The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions t... |
| CVE-2021-20987 | HIGH | 8.6 | 1.1% | Feb 16, 2021 | A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21tha... |
| CVE-2021-20986 | HIGH | 7.5 | 1.0% | Feb 16, 2021 | A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may l... |
| CVE-2021-27232 | HIGH | 8.8 | 1.7% | Feb 16, 2021 | The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stac... |
| CVE-2021-27229 | HIGH | 8.8 | 3.2% | Feb 16, 2021 | Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on t... |
| CVE-2021-21511 | HIGH | 8.1 | 1.0% | Feb 15, 2021 | Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote l... |
| CVE-2021-27211 | HIGH | 7.5 | 3.2% | Feb 15, 2021 | steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data. |
| CVE-2021-27201 | HIGH | 8.8 | 2.6% | Feb 15, 2021 | Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell m... |
| CVE-2021-27219 | HIGH | 7.5 | 3.0% | Feb 15, 2021 | An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer ov... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now