2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-32546HIGH8.8Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely...
CVE-2021-26635HIGH7.8In the code that verifies the file size in the ark library, it is possible to manipulate the offset read from the target...
CVE-2021-3555HIGH8.8A Buffer Overflow vulnerability in the RSTP server component of Eufy Indoor 2K Indoor Camera allows a local attacker to ...
CVE-2021-33014HIGH8.8An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4 control software for versio...
CVE-2021-34360HIGH8.8A cross-site request forgery (CSRF) vulnerability has been reported to affect QNAP device running Proxy Server. If explo...
CVE-2021-40317HIGH8.8Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.
CVE-2021-42860HIGH7.5A stack buffer overflow exists in Mini-XML v3.2. When inputting an unformed XML string to the mxmlLoadString API, it wil...
CVE-2021-42859HIGH7.5A memory leak issue was discovered in Mini-XML v3.2 that could cause a denial of service. NOTE: testing reports are inco...
CVE-2021-44719HIGH8.4Docker Desktop 4.3.0 has Incorrect Access Control.
CVE-2021-32997HIGH7.5The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 Sys...
CVE-2021-32966HIGH7.5Philips Interoperability Solution XDS versions 2.5 through 3.11 and 2018-1 through 2021-1 are vulnerable to clear text t...
CVE-2021-42614HIGH7.8A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or ...
CVE-2021-42613HIGH7.8A double free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a denial of service or possibly hav...
CVE-2021-42612HIGH7.8A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly...
CVE-2021-3717HIGH7.8A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may l...
CVE-2021-32969HIGH7.8Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to an out-of-bounds write condition, which may result...
CVE-2021-32965HIGH7.8Delta Electronics DIAScreen versions prior to 1.1.0 are vulnerable to type confusion, which may allow an attacker to rem...
CVE-2021-4230HIGH7.5A vulnerability has been found in Airfield Online and classified as problematic. This vulnerability affects the path /ba...
CVE-2021-4229HIGH8.8A vulnerability was found in ua-parser-js 0.7.29/0.8.0/1.0.0. It has been rated as critical. This issue affects the cryp...
CVE-2021-42655HIGH8.8SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
CVE-2021-42586HIGH8.8A heap buffer overflow was discovered in copy_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted dwg file.
CVE-2021-42585HIGH8.8A heap buffer overflow was discovered in copy_compressed_bytes in decode_r2007.c in dwgread before 0.12.4 via a crafted ...
CVE-2021-30028HIGH7.2SOOTEWAY Wi-Fi Range Extender v1.5 was discovered to use default credentials (the admin password for the admin account) ...
CVE-2021-32934HIGH7.5The affected ThroughTek P2P products (SDKs using versions before 3.1.5, any versions with nossl tag, device firmware not...
CVE-2021-26631HIGH7.5Improper input validation vulnerability in Mangboard commerce package could lead to occur for abnormal request. A remote...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now