2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-20298HIGH7.5A flaw was found in OpenEXR's B44Compressor. This flaw allows an attacker who can submit a crafted file to be processed ...
CVE-2021-28861HIGH7.4Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multipl...
CVE-2021-3590HIGH8.8A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password t...
CVE-2021-3513HIGH7.5A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. ...
CVE-2021-3481HIGH7.1A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/...
CVE-2021-37289HIGH7.2Insecure Permissions in administration interface in Planex MZK-DP150N 1.42 and 1.43 allows attackers to execute system c...
CVE-2021-36852HIGH8Cross-Site Request Forgery (CSRF) vulnerability in ThimPress WP Hotel Booking plugin <= 1.10.5 at WordPress.
CVE-2021-37409HIGH7.8Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user ...
CVE-2021-33847HIGH7.8Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products be...
CVE-2021-33060HIGH7.8Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially ena...
CVE-2021-23223HIGH7.8Improper initialization for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user ...
CVE-2021-23179HIGH7.1Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before versi...
CVE-2021-30070HIGH7.5An issue was discovered in HestiaCP before v1.3.5. Attackers are able to arbitrarily install packages due to values take...
CVE-2021-26639HIGH7.5This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Re...
CVE-2021-45454HIGH7.5Ampere Altra before SRP 1.08b and Altra Max​ before SRP 2.05 allow information disclosure of power telemetry via HWmon.
CVE-2021-42052HIGH7.5IPESA e-Flow 3.3.6 allows path traversal for reading any file within the web root directory via the lib/js/build/STEReso...
CVE-2021-30490HIGH7.8upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binar...
CVE-2021-29117HIGH7.8A use-after-free vulnerability when parsing a specially crafted file in Esri ArcReader 10.8.1 (and earlier) allows an un...
CVE-2021-44720HIGH7.2In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source...
CVE-2021-40040HIGH7.5Vulnerability of writing data to an arbitrary address in the HW_KEYMASTER module. Successful exploitation of this vulner...
CVE-2021-40034HIGH7.5The video framework has the memory overwriting vulnerability caused by addition overflow. Successful exploitation of thi...
CVE-2021-40030HIGH7.5The My HUAWEI app has a defect in the design. Successful exploitation of this vulnerability may affect data confidential...
CVE-2021-39696HIGH7.8In Task.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation ...
CVE-2021-33646HIGH7.5The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory ...
CVE-2021-33645HIGH7.5The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now