2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-26308HIGH7.5An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to ...
CVE-2021-26306HIGH7.5An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() ...
CVE-2021-3341HIGH7.5A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5...
CVE-2021-3337HIGH7.5The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading re...
CVE-2021-20187HIGH7.2It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to ex...
CVE-2021-20621HIGH8.8Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 fir...
CVE-2021-3326HIGH7.5The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences i...
CVE-2021-22655HIGH7.8Multiple out-of-bounds read issues have been identified in the way the application processes project files, allowing an ...
CVE-2021-22653HIGH7.8Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an...
CVE-2021-22641HIGH7.8A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an a...
CVE-2021-22639HIGH7.8An uninitialized pointer issue has been identified in the way the application processes project files, allowing an attac...
CVE-2021-22637HIGH7.8Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, all...
CVE-2021-26118HIGH7.5While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Ap...
CVE-2021-26117HIGH7.5The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for ...
CVE-2021-25247HIGH7.8A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker...
CVE-2021-25312HIGH8.8HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS au...
CVE-2021-3317HIGH8.8KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of ...
CVE-2021-3165HIGH8.8SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI.
CVE-2021-1070HIGH7.1NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, L4T versions prior to 32.5, contains a v...
CVE-2021-3309HIGH8.1packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by t...
CVE-2021-3156HIGH7.8Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege...
CVE-2021-22159HIGH7.8Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Managemen...
CVE-2021-3297HIGH7.8On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
CVE-2021-3291HIGH7.2Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod...
CVE-2021-3223HIGH7.5Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now