2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-42532HIGH7.8XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res...
CVE-2021-42531HIGH7.8XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res...
CVE-2021-42530HIGH7.8XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res...
CVE-2021-42529HIGH7.8XMP Toolkit SDK version 2021.07 (and earlier) is affected by a stack-based buffer overflow vulnerability potentially res...
CVE-2021-3750HIGH8.2A DMA reentrancy issue was found in the USB EHCI controller emulation of QEMU. EHCI does not verify if the Buffer Pointe...
CVE-2021-25002HIGH7.5The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which co...
CVE-2021-46790HIGH7.8ntfsck in NTFS-3G through 2021.8.22 has a heap-based buffer overflow involving buffer+512*3-2. NOTE: the upstream positi...
CVE-2021-36784HIGH7.2A Improper Privilege Management vulnerability in SUSE Rancher allows users with the restricted-admin role to escalate to...
CVE-2021-36778HIGH7.5A Incorrect Authorization vulnerability in SUSE Rancher allows administrators of third-party repositories to gather cred...
CVE-2021-40822HIGH7.5GeoServer through 2.18.5 and 2.19.x through 2.19.2 allows SSRF via the option for setting a proxy host.
CVE-2021-4207HIGH8.2A flaw was found in the QXL display device emulation in QEMU. A double fetch of guest controlled values `cursor->header....
CVE-2021-4206HIGH8.2A flaw was found in the QXL display device emulation in QEMU. An integer overflow in the cursor_alloc() function can lea...
CVE-2021-36207HIGH8.8Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow ...
CVE-2021-43937HIGH8.8Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, c...
CVE-2021-39082HIGH7.5IBM UrbanCode Deploy (UCD) 7.1.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to de...
CVE-2021-44595HIGH8.8Wondershare Dr. Fone Latest version as of 2021-12-06 is vulnerable to Incorrect Access Control. A normal user can send m...
CVE-2021-41942HIGH7.5The Magic CMS MSVOD v10 video system has a SQL injection vulnerability. Attackers can use vulnerabilities to obtain sens...
CVE-2021-43939HIGH8.8Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by i...
CVE-2021-33436HIGH7.3NoMachine for Windows prior to version 6.15.1 and 7.5.2 suffer from local privilege escalation due to the lack of safe D...
CVE-2021-3523HIGH7.5A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. T...
CVE-2021-38919HIGH7.5IBM QRadar SIEM 7.3, 7.4, and 7.5 in some senarios may reveal authorized service tokens to other QRadar users. IBM X-For...
CVE-2021-38878HIGH7.5IBM QRadar 7.3, 7.4, and 7.5 could allow a malicious actor to impersonate an actor due to key exchange without entity au...
CVE-2021-34602HIGH8.8In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticate...
CVE-2021-34592HIGH8.8In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticate...
CVE-2021-34591HIGH7.8In Bender/ebee Charge Controllers in multiple versions are prone to Local privilege Escalation. An authenticated attacke...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now