2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26308 | HIGH | 7.5 | 1.5% | Jan 29, 2021 | An issue was discovered in the marc crate before 2.0.0 for Rust. A user-provided Read implementation can gain access to ... |
| CVE-2021-26306 | HIGH | 7.5 | 1.3% | Jan 29, 2021 | An issue was discovered in the raw-cpuid crate before 9.0.0 for Rust. It has unsound transmute calls within as_string() ... |
| CVE-2021-3341 | HIGH | 7.5 | 1.3% | Jan 29, 2021 | A path traversal vulnerability in the DxWebEngine component of DH2i DxEnterprise and DxOdyssey for Windows, version 19.5... |
| CVE-2021-3337 | HIGH | 7.5 | 11.5% | Jan 28, 2021 | The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading re... |
| CVE-2021-20187 | HIGH | 7.2 | 1.6% | Jan 28, 2021 | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to ex... |
| CVE-2021-20621 | HIGH | 8.8 | 0.6% | Jan 28, 2021 | Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 fir... |
| CVE-2021-3326 | HIGH | 7.5 | 3.1% | Jan 27, 2021 | The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences i... |
| CVE-2021-22655 | HIGH | 7.8 | 1.2% | Jan 27, 2021 | Multiple out-of-bounds read issues have been identified in the way the application processes project files, allowing an ... |
| CVE-2021-22653 | HIGH | 7.8 | 1.2% | Jan 27, 2021 | Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an... |
| CVE-2021-22641 | HIGH | 7.8 | 2.1% | Jan 27, 2021 | A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an a... |
| CVE-2021-22639 | HIGH | 7.8 | 1.9% | Jan 27, 2021 | An uninitialized pointer issue has been identified in the way the application processes project files, allowing an attac... |
| CVE-2021-22637 | HIGH | 7.8 | 2.1% | Jan 27, 2021 | Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, all... |
| CVE-2021-26118 | HIGH | 7.5 | 4.0% | Jan 27, 2021 | While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Ap... |
| CVE-2021-26117 | HIGH | 7.5 | 11.2% | Jan 27, 2021 | The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for ... |
| CVE-2021-25247 | HIGH | 7.8 | 0.7% | Jan 27, 2021 | A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker... |
| CVE-2021-25312 | HIGH | 8.8 | 1.0% | Jan 27, 2021 | HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS au... |
| CVE-2021-3317 | HIGH | 8.8 | 41.4% | Jan 26, 2021 | KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of ... |
| CVE-2021-3165 | HIGH | 8.8 | 2.2% | Jan 26, 2021 | SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI. |
| CVE-2021-1070 | HIGH | 7.1 | 0.3% | Jan 26, 2021 | NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, L4T versions prior to 32.5, contains a v... |
| CVE-2021-3309 | HIGH | 8.1 | 1.7% | Jan 26, 2021 | packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by t... |
| CVE-2021-3156 | HIGH | 7.8 | 99.3% | Jan 26, 2021 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege... |
| CVE-2021-22159 | HIGH | 7.8 | 0.3% | Jan 26, 2021 | Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Managemen... |
| CVE-2021-3297 | HIGH | 7.8 | 20.5% | Jan 26, 2021 | On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access. |
| CVE-2021-3291 | HIGH | 7.2 | 16.8% | Jan 26, 2021 | Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod... |
| CVE-2021-3223 | HIGH | 7.5 | 16.5% | Jan 26, 2021 | Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now