2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31845HIGH7.3A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in th...
CVE-2021-31844HIGH7.3A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a loc...
CVE-2021-31843HIGH7.8Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Up...
CVE-2021-31842MEDIUM5.5XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 202...
CVE-2021-39327MEDIUM5.3The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosur...
CVE-2021-23442CRITICAL9.8This affects all versions of package @cookiex/deep. The global proto object can be polluted using the __proto__ object.
CVE-2021-41303CRITICAL9.8Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authe...
CVE-2021-3812MEDIUM6.1adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3811MEDIUM6.1adminlte is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3810HIGH7.5code-server is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3807HIGH7.5ansi-regex is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3804HIGH7.5taro is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-3803HIGH7.5nth-check is vulnerable to Inefficient Regular Expression Complexity
CVE-2021-30261HIGH7.8Possible integer and heap overflow due to lack of input command size validation while handling beacon template update co...
CVE-2021-30260HIGH7.8Possible Integer overflow to buffer overflow issue can occur due to improper validation of input parameters when extscan...
CVE-2021-1976CRITICAL9.8A use after free can occur due to improper validation of P2P device address in PD Request frame in Snapdragon Auto, Snap...
CVE-2021-1947HIGH7.8Use-after-free vulnerability in kernel graphics driver because of storing an invalid pointer in Snapdragon Compute, Snap...
CVE-2021-1939MEDIUM5.5Null pointer dereference occurs due to improper validation when the preemption feature enablement is toggled in Snapdrag...
CVE-2021-3805HIGH7.5object-path is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-20828MEDIUM6.1Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a r...
CVE-2021-20825MEDIUM6.1Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and e...
CVE-2021-20791CRITICAL9.3Improper access control vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to bypass access restr...
CVE-2021-20790CRITICAL9.6Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier allows an attacker to execu...
CVE-2021-41314HIGH8.8Certain NETGEAR smart switches are affected by a \n injection in the web UI's password field, which - due to several fau...
CVE-2021-40670CRITICAL9.8SQL Injection vulnerability exists in Wuzhi CMS 4.1.0 via the keywords iparameter under the /coreframe/app/order/admin/c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now