2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-33644HIGH8.1An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of mallo...
CVE-2021-46304HIGH7.5A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions), CP-8000 MASTER MODULE WI...
CVE-2021-37150HIGH7.5Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure ...
CVE-2021-32771HIGH8.1Contiki-NG is an open-source, cross-platform operating system for IoT devices. In affected versions it is possible to ca...
CVE-2021-39088HIGH7.8IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unkno...
CVE-2021-22642HIGH7.5An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
CVE-2021-42537HIGH7.5VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents...
CVE-2021-38417HIGH7.5VISAM VBASE version 11.6.0.6 is vulnerable to improper access control via the web-remote endpoint, which may allow an un...
CVE-2021-38410HIGH7.8AVEVA Software Platform Common Services (PCS) Portal versions 4.5.2, 4.5.1, 4.5.0, and 4.4.6 are vulnerable to DLL hijac...
CVE-2021-40180HIGH7.5In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's addr...
CVE-2021-33057HIGH7.5The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCE...
CVE-2021-33453HIGH7.8An issue was discovered in lrzip version 0.641. There is a use-after-free in ucompthread() in stream.c:1538.
CVE-2021-40336HIGH8.8A vulnerability exists in the http web interface where the web interface does not validate data in an HTTP header. This ...
CVE-2021-40335HIGH8.8A vulnerability exists in the HTTP web interface where the web interface does not sufficiently verify if a well-formed, ...
CVE-2021-46829HIGH7.8GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames i...
CVE-2021-29755HIGH7.5IBM QRadar SIEM 7.3, 7.4, and 7.5 does not preform proper certificate validation for some inter-host communications. IBM...
CVE-2021-46828HIGH7.5In libtirpc before 1.3.3rc1, remote attackers could exhaust the file descriptors of a process that uses libtirpc because...
CVE-2021-41031HIGH7.8A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior an...
CVE-2021-44954HIGH7.8In QVIS NVR DVR before 2021-12-13, an attacker can escalate privileges from a qvisdvr user to the root user by abusing a...
CVE-2021-42923HIGH7.3ShowMyPC 3606 on Windows suffers from a DLL hijack vulnerability. If an attacker overwrites the file %temp%\ShowMyPC\-Sh...
CVE-2021-40150HIGH7.5The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/ directory that is mapp...
CVE-2021-24655HIGH7.5The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related t...
CVE-2021-34538HIGH7.5Apache Hive before 3.1.3 "CREATE" and "DROP" function operations does not check for necessary authorization of involved ...
CVE-2021-34987HIGH8.2This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (...
CVE-2021-34986HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now