2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43016MEDIUM5.5Adobe InCopy version 16.4 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially...
CVE-2021-43015HIGH7.8Adobe InCopy version 16.4 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a m...
CVE-2021-42738HIGH7.8Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a ...
CVE-2021-42737HIGH7.8Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a ...
CVE-2021-42733MEDIUM5.5Adobe Bridge version 11.1.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a special...
CVE-2021-42727HIGH7.8Adobe Bridge 11.1.1 (and earlier) is affected by a stack overflow vulnerability due to insecure handling of a crafted fi...
CVE-2021-40775HIGH7.8Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a ...
CVE-2021-40774MEDIUM5.5Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a speciall...
CVE-2021-40773MEDIUM5.5Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a speciall...
CVE-2021-40772HIGH7.8Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a ...
CVE-2021-40771HIGH7.8Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a ...
CVE-2021-40770HIGH7.8Adobe Prelude version 10.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a ...
CVE-2021-3943CRITICAL9.8A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A...
CVE-2021-3935HIGH8.1When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries...
CVE-2021-26614CRITICAL9.8ius_get.cgi in IpTime C200 camera allows remote code execution. A remote attacker may send a crafted parameters to the e...
CVE-2021-43582HIGH7.8A Use-After-Free Remote Vulnerability exists when reading a DWG file using Open Design Alliance Drawings SDK before 2022...
CVE-2021-43581HIGH8.8An Out-of-Bounds Read vulnerability exists when reading a U3D file using Open Design Alliance PRC SDK before 2022.11. Th...
CVE-2021-43557HIGH7.5The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full...
CVE-2021-38378MEDIUM4.3OX App Suite 7.10.5 allows Information Exposure because a caching mechanism can caused a Modified By response to show a ...
CVE-2021-38377MEDIUM6.1OX App Suite through 7.10.5 allows XSS via JavaScript code in an anchor HTML comment within truncated e-mail, because th...
CVE-2021-38376MEDIUM5.3OX App Suite through 7.10.5 has Incorrect Access Control for retrieval of session information via the rampup action of t...
CVE-2021-38375MEDIUM6.1OX App Suite through 7.10.5 allows XSS via the alt attribute of an IMG element in a truncated e-mail message.
CVE-2021-38374MEDIUM5.4OX App Suite through through 7.10.5 allows XSS via a crafted snippet that has an app loader reference within an app load...
CVE-2021-38146HIGH7.5The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary ...
CVE-2021-33495MEDIUM6.1OX App Suite 7.10.5 allows XSS via an OX Chat system message.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now