2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-24412MEDIUM5.4The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters fro...
CVE-2021-38442HIGH7.8FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project...
CVE-2021-38440LOW3.3FATEK Automation WinProladder versions 3.30 and prior is vulnerable to an out-of-bounds read, which may allow an attacke...
CVE-2021-38438HIGH7.8A use after free vulnerability in FATEK Automation WinProladder versions 3.30 and prior may be exploited when a valid us...
CVE-2021-38436HIGH7.8FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project...
CVE-2021-38434HIGH7.8FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project...
CVE-2021-38430HIGH7.8FATEK Automation WinProladder versions 3.30 and prior proper validation of user-supplied data when parsing project files...
CVE-2021-38426HIGH7.8FATEK Automation WinProladder versions 3.30 and prior lacks proper validation of user-supplied data when parsing project...
CVE-2021-38389CRITICAL9.8Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker...
CVE-2021-33023CRITICAL9.8Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker ...
CVE-2021-22961CRITICAL9.8A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary co...
CVE-2021-22942MEDIUM6.1A possible open redirect vulnerability in the Host Authorization middleware in Action Pack >= 6.0.0 that could allow att...
CVE-2021-21797HIGH7.8An exploitable double-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted d...
CVE-2021-21796HIGH7.8An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafte...
CVE-2021-41611HIGH7.5An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, S...
CVE-2021-38562HIGH7.5Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive informati...
CVE-2021-42566MEDIUM6.1myfactory.FMS before 7.1-912 allows XSS via the Error parameter.
CVE-2021-42565MEDIUM6.1myfactory.FMS before 7.1-912 allows XSS via the UID parameter.
CVE-2021-36097MEDIUM4.3Agents are able to lock the ticket without the "Owner" permission. Once the ticket is locked, it could be moved to the q...
CVE-2021-38297CRITICAL9.8Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM...
CVE-2021-27561CRITICAL9.8Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, ...
CVE-2021-41320MEDIUM5.5A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with higher privilege than th...
CVE-2021-29745HIGH8.8IBM Cognos Analytics 11.1.7 and 11.2.0 is vulnerable to priviledge escalation where a lower evel user could have access ...
CVE-2021-29679HIGH8.8IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neu...
CVE-2021-28021HIGH7.8Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now