2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-0109HIGH7.8Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authent...
CVE-2021-22553HIGH7.5Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not ...
CVE-2021-22858HIGH8.8Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrar...
CVE-2021-22857HIGH7.5The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to dow...
CVE-2021-22856HIGH7.5The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into...
CVE-2021-23885HIGH8.8Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain eleva...
CVE-2021-20655HIGH7.2FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary ...
CVE-2021-26934HIGH7.8An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) ...
CVE-2021-26930HIGH7.8An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend,...
CVE-2021-27102HIGH7.8Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version i...
CVE-2021-20075HIGH7.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd.
CVE-2021-20074HIGH8.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and ...
CVE-2021-20073HIGH8.8Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries.
CVE-2021-20072HIGH7.2Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an ...
CVE-2021-21316HIGH7.8less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10.,...
CVE-2021-23840HIGH7.5Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases...
CVE-2021-21315HIGH7.8The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions t...
CVE-2021-20987HIGH8.6A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21tha...
CVE-2021-20986HIGH7.5A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may l...
CVE-2021-27232HIGH8.8The RTSPLive555.dll ActiveX control in Pelco Digital Sentry Server 7.18.72.11464 has a SetCameraConnectionParameter stac...
CVE-2021-27229HIGH8.8Mumble before 1.3.4 allows remote code execution if a victim navigates to a crafted URL on a server list and clicks on t...
CVE-2021-21511HIGH8.1Dell EMC Avamar Server, versions 19.3 and 19.4 contain an Improper Authorization vulnerability in the web UI. A remote l...
CVE-2021-27211HIGH7.5steghide 0.5.1 relies on a certain 32-bit seed value, which makes it easier for attackers to detect hidden data.
CVE-2021-27201HIGH8.8Endian Firewall Community (aka EFW) 3.3.2 allows remote authenticated users to execute arbitrary OS commands via shell m...
CVE-2021-27219HIGH7.5An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer ov...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now