2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0660MEDIUM4.9In ccu, there is a possible out of bounds read due to incorrect error handling. This could lead to information disclosur...
CVE-2021-0612HIGH7.8In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ...
CVE-2021-0611HIGH7.8In m4u, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege ...
CVE-2021-0610HIGH7.8In memory management driver, there is a possible memory corruption due to an integer overflow. This could lead to local ...
CVE-2021-0425MEDIUM5.5In memory management driver, there is a possible side channel information disclosure. This could lead to local informati...
CVE-2021-0424MEDIUM5.5In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local de...
CVE-2021-0423MEDIUM5.5In memory management driver, there is a possible information disclosure due to uninitialized data. This could lead to lo...
CVE-2021-0422MEDIUM5.5In memory management driver, there is a possible system crash due to a missing bounds check. This could lead to local de...
CVE-2021-0421MEDIUM5.5In memory management driver, there is a possible information disclosure due to a missing bounds check. This could lead t...
CVE-2021-23054MEDIUM6.1On version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11....
CVE-2021-20317MEDIUM4.4A flaw was found in the Linux kernel. A corrupted timer tree caused the task wakeup to be missing in the timerqueue_add ...
CVE-2021-34570HIGH7.5Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through spe...
CVE-2021-41580MEDIUM5.3The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an access token...
CVE-2021-41385MEDIUM6.5The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain...
CVE-2021-41329MEDIUM6.5Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not cons...
CVE-2021-40981HIGH7.3ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the pu...
CVE-2021-40349MEDIUM5.3e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET ...
CVE-2021-38299CRITICAL9.8Webauthn Framework 3.3.x before 3.3.4 has Incorrect Access Control. An attacker that controls a user's system is able to...
CVE-2021-31606HIGH7.5furlongm openvpn-monitor through 1.1.3 allows Authorization Bypass to disconnect arbitrary clients.
CVE-2021-31605HIGH7.5furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This ca...
CVE-2021-31604MEDIUM6.5furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.
CVE-2021-34351CRITICAL9.8A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ...
CVE-2021-34349HIGH7.2A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ...
CVE-2021-34348CRITICAL9.8A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability ...
CVE-2021-41617HIGH7sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalatio...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now