2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41163CRITICAL9.8Discourse is an open source platform for community discussion. In affected versions maliciously crafted requests could l...
CVE-2021-42299MEDIUM5.6Microsoft Surface Pro 3 Security Feature Bypass Vulnerability
CVE-2021-42771HIGH7.8Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python ob...
CVE-2021-42766CRITICAL9.1The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service...
CVE-2021-42765HIGH7.5The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to leverage network delay to...
CVE-2021-42764CRITICAL9.1The Proof-of-Stake (PoS) Ethereum consensus protocol through 2021-10-19 allows an adversary to cause a denial of service...
CVE-2021-42762MEDIUM5.3BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed...
CVE-2021-41167HIGH7.5modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In...
CVE-2021-38896MEDIUM6.1IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2021-41135MEDIUM6.5The Cosmos-SDK is a framework for building blockchain applications in Golang. Affected versions of the SDK were vulnerab...
CVE-2021-21749CRITICAL9.8ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to...
CVE-2021-21748CRITICAL9.8ZTE MF971R product has two stack-based buffer overflow vulnerabilities. An attacker could exploit the vulnerabilities to...
CVE-2021-21745MEDIUM4.3ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use th...
CVE-2021-21744HIGH7.5ZTE MF971R product has a configuration file control vulnerability. An attacker could use this vulnerability to modify th...
CVE-2021-21743MEDIUM4.3ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP re...
CVE-2021-3542Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-42739. Reason: This candidate is a reservation d...
CVE-2021-21747MEDIUM6.1ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie informatio...
CVE-2021-21746MEDIUM6.1ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie informatio...
CVE-2021-23452CRITICAL9.8This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
CVE-2021-25972MEDIUM4.9In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload fea...
CVE-2021-25971MEDIUM4.3In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes...
CVE-2021-25970HIGH8.8Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s p...
CVE-2021-25969MEDIUM6.1In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attack...
CVE-2021-35666MEDIUM5.9Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). The supported vers...
CVE-2021-35665MEDIUM6.1Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported vers...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now