2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-36461HIGH8.8An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upl...
CVE-2021-26384HIGH7.8A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info da...
CVE-2021-45492HIGH7.8In Sage 300 ERP (formerly accpac) through 6.8.x, the installer configures the C:\Sage\Sage300\Runtime directory to be th...
CVE-2021-46741HIGH7.5The basic framework and setting module have defects, which were introduced during the design. Successful exploitation of...
CVE-2021-41396HIGH7.5Live555 through 1.08 does not handle socket connections properly. A huge number of incoming socket connections in a shor...
CVE-2021-40012HIGH7.5Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitatio...
CVE-2021-39999HIGH7.5There is a buffer overflow vulnerability in eSE620X vESS V100R001C10SPC200 and V100R001C20SPC200. An attacker can exploi...
CVE-2021-38289HIGH8.8An issue has been discovered in Novastar-VNNOX-iCare Novaicare 7.16.0 that gives attacker privilege escalation and allow...
CVE-2021-36668HIGH7.8URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parame...
CVE-2021-36667HIGH7.8Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via craf...
CVE-2021-36666HIGH7.8An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDeco...
CVE-2021-36665HIGH7.8An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgr...
CVE-2021-44221HIGH7.5A vulnerability has been identified in SIMATIC eaSie Core Package (All versions < V22.00). The affected systems do not p...
CVE-2021-41037HIGH8In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoin...
CVE-2021-31645HIGH7.5An issue was discovered in glFTPd 2.11a that allows remote attackers to cause a denial of service via exceeding the conn...
CVE-2021-4234HIGH7.5OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset pac...
CVE-2021-3697HIGH7A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written...
CVE-2021-23163HIGH8.8JFrog Artifactory prior to version 7.33.6 and 6.23.38, is vulnerable to CSRF ( Cross-Site Request Forgery) for specific ...
CVE-2021-44915HIGH7.2Taocms 3.0.2 was discovered to contain a blind SQL injection vulnerability via the function Edit category.
CVE-2021-43116HIGH8.8An Access Control vulnerability exists in Nacos 2.0.3 in the access prompt page; enter username and password, click on l...
CVE-2021-41995HIGH7.5A misconfiguration of RSA in PingID Mac Login prior to 1.1 is vulnerable to pre-computed dictionary attacks, leading to ...
CVE-2021-38941HIGH8.1IBM CloudPak for Multicloud Monitoring 2.0 and 2.3 has a few containers running in privileged mode which is vulnerable t...
CVE-2021-37770HIGH7.2Nucleus CMS v3.71 is affected by a file upload vulnerability. In this vulnerability, we can use upload to change the upl...
CVE-2021-3434HIGH7.8Stack based buffer overflow in le_ecred_conn_req(). Zephyr versions >= v2.5.0 Stack-based Buffer Overflow (CWE-121). For...
CVE-2021-3432HIGH7.5Invalid interval in CONNECT_IND leads to Division by Zero. Zephyr versions >= v1.14.0 Divide By Zero (CWE-369). For more...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now