2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26322HIGH7.5Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
CVE-2021-26312MEDIUM5.5Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device ...
CVE-2021-38949MEDIUM5.5IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local u...
CVE-2021-38882MEDIUM4.4IBM Spectrum Scale 5.1.0 through 5.1.1.1 could allow a privileged admin to destroy filesystem audit logging records befo...
CVE-2021-43362CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allow...
CVE-2021-43361CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in MedData HBYS allow...
CVE-2021-3958CRITICAL9.8Improper Handling of Parameters vulnerability in Ipack Automation Systems Ipack SCADA Software allows : Blind SQL Inject...
CVE-2021-30216Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-42114HIGH8.3Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitiga...
CVE-2021-37580CRITICAL9.8A flaw was found in Apache ShenYu Admin. The incorrect use of JWT in ShenyuAdminBootstrap allows an attacker to bypass a...
CVE-2021-25985CRITICAL9.8In Factor (App Framework & Headless CMS) v1.0.4 to v1.8.30, improperly invalidate a user’s session even after the user l...
CVE-2021-25984MEDIUM6.1In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.3 to v1.8.30, are vulnerable to stored Cross-Site S...
CVE-2021-25983MEDIUM6.1In Factor (App Framework & Headless CMS) forum plugin, versions v1.3.8 to v1.8.30, are vulnerable to reflected Cross-Sit...
CVE-2021-25982MEDIUM6.1In Factor (App Framework & Headless CMS) forum plugin, versions 1.3.5 to 1.8.30, are vulnerable to reflected Cross-Site ...
CVE-2021-25965HIGH8.8In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated...
CVE-2021-25940HIGH8In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration. When a user’s password is...
CVE-2021-25976HIGH8.1In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing variou...
CVE-2021-42337MEDIUM4.3The permission control of AIFU cashier management salary query function can be bypassed, thus after obtaining general us...
CVE-2021-41271MEDIUM5.3Discourse is a platform for community discussion. In affected versions a maliciously crafted request could cause an erro...
CVE-2021-42386HIGH7.2A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte...
CVE-2021-42385HIGH7.2A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte...
CVE-2021-42384HIGH7.2A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte...
CVE-2021-42383HIGH7.2A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte...
CVE-2021-42382HIGH7.2A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte...
CVE-2021-42381HIGH7.2A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now