2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-3195HIGH7.5bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin di...
CVE-2021-3164HIGH8.8ChurchRota 2.6.4 is vulnerable to authenticated remote code execution. The user does not need to have file upload permis...
CVE-2021-3115HIGH7.5Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when ...
CVE-2021-26267HIGH7.5cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).
CVE-2021-26266HIGH7.5cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).
CVE-2021-26026HIGH7.8PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDS...
CVE-2021-26025HIGH7.8PlugIns\IDE_ACDStd.apl in ACDSee Professional 2021 14.0 1721 has a User Mode Write Access Violation starting at IDE_ACDS...
CVE-2021-25908HIGH7.5An issue was discovered in the fil-ocl crate through 2021-01-04 for Rust. From<EventList> can lead to a double free.
CVE-2021-25906HIGH7.5An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a dou...
CVE-2021-25904HIGH7.5An issue was discovered in the av-data crate before 0.3.0 for Rust. A raw pointer is dereferenced, leading to a read of ...
CVE-2021-25903HIGH7.5An issue was discovered in the cache crate through 2021-01-01 for Rust. A raw pointer is dereferenced.
CVE-2021-25902HIGH7.5An issue was discovered in the glsl-layout crate before 0.4.0 for Rust. When a panic occurs, map_array can perform a dou...
CVE-2021-25864HIGH7.5node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in fil...
CVE-2021-25863HIGH8.8Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
CVE-2021-22698HIGH7.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody...
CVE-2021-22697HIGH7.8A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists in the EcoStruxure Power Build - Rapsody...
CVE-2021-21723HIGH7.5Some ZTE products have a DoS vulnerability. Due to the improper handling of memory release in some specific scenarios, a...
CVE-2021-21272HIGH7.7ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI ...
CVE-2021-22847HIGH8.8Hyweb HyCMS-J1's API fail to filter POST request parameters. Remote attackers can inject SQL syntax and execute commands...
CVE-2021-1068HIGH7.8NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vulnerability in the NVDEC component, in which an attacker can...
CVE-2021-1248HIGH7.2Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authen...
CVE-2021-1247HIGH8.8Multiple vulnerabilities in certain REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authen...
CVE-2021-1241HIGH7.5Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of s...
CVE-2021-1222HIGH8.1A vulnerability in the web-based management interface of Cisco Smart Software Manager Satellite could allow an authentic...
CVE-2021-1219HIGH7.8A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local attacker to access sensiti...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now