2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0615MEDIUM5.5In flv extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local informatio...
CVE-2021-0614MEDIUM5.5In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local info...
CVE-2021-0613MEDIUM5.5In asf extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local info...
CVE-2021-0414MEDIUM5.5In flv extractor, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local informa...
CVE-2021-0413MEDIUM5.5In flv extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local informa...
CVE-2021-0412MEDIUM5.5In flv extractor, there is a possible out of bounds read due to a missing bounds check. This could lead to local informa...
CVE-2021-0411MEDIUM5.5In flv extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local informatio...
CVE-2021-0410MEDIUM5.5In flv extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local info...
CVE-2021-0409MEDIUM5.5In flv extractor, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local info...
CVE-2021-40865CRITICAL9.8An Unsafe Deserialization vulnerability exists in the worker services of the Apache Storm supervisor server allowing pre...
CVE-2021-38294CRITICAL9.8A Command Injection vulnerability exists in the getTopologyHistory service of the Apache Storm 2.x prior to 2.2.1 and Ap...
CVE-2021-35231MEDIUM6.7As a result of an unquoted service path vulnerability present in the Kiwi Syslog Server Installation Wizard, a local att...
CVE-2021-25977MEDIUM5.4In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creat...
CVE-2021-40527HIGH7.5Exposure of senstive information to an unauthorised actor in the "com.onepeloton.erlich" mobile application up to and in...
CVE-2021-40526MEDIUM5.3Incorrect calculation of buffer size vulnerability in Peleton TTR01 up to and including PTV55G allows a remote attacker ...
CVE-2021-40371CRITICAL9.8Gridpro Request Management for Windows Azure Pack before 2.0.7912 allows Directory Traversal for remote code execution, ...
CVE-2021-21703HIGH7In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI w...
CVE-2021-42258CRITICAL9.8BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution...
CVE-2021-42840HIGH8.8SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta...
CVE-2021-42556MEDIUM5.5Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to lo...
CVE-2021-41171HIGH8.8eLabFTW is an open source electronic lab notebook manager for research teams. In versions of eLabFTW before 4.1.0, it al...
CVE-2021-29835MEDIUM6.1IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2021-42836HIGH7.5GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
CVE-2021-42542HIGH8.8The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.
CVE-2021-42540HIGH8.8The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can l...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now