2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3195 | HIGH | 7.5 | 1.2% | Jan 26, 2021 | bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin di... |
| CVE-2021-3164 | HIGH | 8.8 | 4.2% | Jan 26, 2021 | ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permis... |
| CVE-2021-3115 | HIGH | 7.5 | 6.4% | Jan 26, 2021 | Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when ... |
| CVE-2021-26267 | HIGH | 7.5 | 0.9% | Jan 26, 2021 | cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579). |
| CVE-2021-26266 | HIGH | 7.5 | 0.9% | Jan 26, 2021 | cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578). |
| CVE-2021-26026 | HIGH | 7.8 | 0.7% | Jan 26, 2021 | PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDS... |
| CVE-2021-26025 | HIGH | 7.8 | 0.7% | Jan 26, 2021 | PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDS... |
| CVE-2021-25908 | HIGH | 7.5 | 1.3% | Jan 26, 2021 | An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free. |
| CVE-2021-25906 | HIGH | 7.5 | 1.3% | Jan 26, 2021 | An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a dou... |
| CVE-2021-25904 | HIGH | 7.5 | 1.3% | Jan 26, 2021 | An issue was discovered in the av-data crate before 0.3.0 for Rust. A raw pointer is dereferenced, leading to a read of ... |
| CVE-2021-25903 | HIGH | 7.5 | 1.4% | Jan 26, 2021 | An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced. |
| CVE-2021-25902 | HIGH | 7.5 | 1.4% | Jan 26, 2021 | An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a dou... |
| CVE-2021-25864 | HIGH | 7.5 | 9.3% | Jan 26, 2021 | node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in fil... |
| CVE-2021-25863 | HIGH | 8.8 | 1.2% | Jan 26, 2021 | Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account. |
| CVE-2021-22698 | HIGH | 7.8 | 3.9% | Jan 26, 2021 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody... |
| CVE-2021-22697 | HIGH | 7.8 | 3.5% | Jan 26, 2021 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody... |
| CVE-2021-21723 | HIGH | 7.5 | 1.2% | Jan 26, 2021 | Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a... |
| CVE-2021-21272 | HIGH | 7.7 | 1.4% | Jan 25, 2021 | ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI ... |
| CVE-2021-22847 | HIGH | 8.8 | 1.6% | Jan 22, 2021 | Hyweb HyCMS-J1's API fail to filter POST request parameters. Remote attackers can inject SQL syntax and execute commands... |
| CVE-2021-1068 | HIGH | 7.8 | 0.4% | Jan 20, 2021 | NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the NVDEC component, in which an attacker can... |
| CVE-2021-1248 | HIGH | 7.2 | 1.9% | Jan 20, 2021 | Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authen... |
| CVE-2021-1247 | HIGH | 8.8 | 1.9% | Jan 20, 2021 | Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authen... |
| CVE-2021-1241 | HIGH | 7.5 | 1.4% | Jan 20, 2021 | Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of s... |
| CVE-2021-1222 | HIGH | 8.1 | 1.2% | Jan 20, 2021 | A vulnerability in the web-based management interface of Cisco Smart Software Manager Satellite could allow an authentic... |
| CVE-2021-1219 | HIGH | 7.8 | 0.3% | Jan 20, 2021 | A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensiti... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now