2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-40893HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-data v0.1.1 when validating craf...
CVE-2021-40892HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-color v2.1.0 when handling craft...
CVE-2021-41638HIGH7.5The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to a...
CVE-2021-41637HIGH7.1Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configurati...
CVE-2021-41635HIGH8.8When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse...
CVE-2021-40956HIGH7.5LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obta...
CVE-2021-40955HIGH7.2SQL injection exists in LaiKetui v3.5.0 the background administrator list.
CVE-2021-40511HIGH7.5OBDA systems’ Mastro 1.0 is vulnerable to XML Entity Expansion (aka “billion laughs”) attack allowing denial of service.
CVE-2021-40510HIGH7.5XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.
CVE-2021-41683HIGH7.8There is a stack-overflow at ecma-helpers.c:326 in ecma_get_lex_env_type in JerryScript 2.4.0
CVE-2021-41682HIGH7.8There is a heap-use-after-free at ecma-helpers-string.c:1940 in ecma_compare_ecma_non_direct_strings in JerryScript 2.4....
CVE-2021-45918HIGH7.5NHI’s health insurance web service component has insufficient validation for input string length, which can result in he...
CVE-2021-45025HIGH7.5ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to C...
CVE-2021-41490HIGH7.5Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.
CVE-2021-46820HIGH8.1Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /sho...
CVE-2021-37764HIGH8.1Arbitrary File Deletion vulnerability in XOS-Shop xos_shop_system 1.0.9 via current_manufacturer_image parameter to /sho...
CVE-2021-3675HIGH7.1Improper Input Validation vulnerability in synaTEE.signed.dll of Synaptics Fingerprint Driver allows a local authorized ...
CVE-2021-41402HIGH8.8flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP co...
CVE-2021-43755HIGH7.8Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerab...
CVE-2021-42735HIGH7.8Adobe Photoshop version 22.5.1 (and earlier versions ) is affected by an Access of Memory Location After End of Buffer v...
CVE-2021-25261HIGH7.8Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker...
CVE-2021-43756HIGH7.8Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthe...
CVE-2021-43754HIGH7.8Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling ...
CVE-2021-42732HIGH7.8Access of Memory Location After End of Buffer (CWE-788)
CVE-2021-40727HIGH7.8Access of Memory Location After End of Buffer (CWE-788

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now