2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-1981CRITICAL9.1Possible buffer over read due to improper IE size check of Bearer capability IE in MT setup request from network in Snap...
CVE-2021-1975CRITICAL9.8Possible heap overflow due to improper length check of domain while parsing the DNS response in Snapdragon Auto, Snapdra...
CVE-2021-42775CRITICAL9.1Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly...
CVE-2021-42774CRITICAL9.8Broadcom Emulex HBA Manager/One Command Manager versions before 11.4.425.0 and 12.8.542.31, if not installed in Strictly...
CVE-2021-34422CRITICAL9The Keybase Client for Windows before version 5.7.0 contains a path traversal vulnerability when checking the name of a ...
CVE-2021-3907CRITICAL9.8OctoRPKI does not escape a URI with a filename containing "..", this allows a repository to create a file, (ex. rsync://...
CVE-2021-43350CRITICAL9.8An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the P...
CVE-2021-42847CRITICAL9.8Zoho ManageEngine ADAudit Plus before 7006 allows attackers to write to, and execute, arbitrary files.
CVE-2021-42002CRITICAL9.8Zoho ManageEngine ADManager Plus before 7115 is vulnerable to a filter bypass that leads to file-upload remote code exec...
CVE-2021-41833CRITICAL9.8Zoho ManageEngine Patch Connect Plus before 90099 is vulnerable to unauthenticated remote code execution.
CVE-2021-41081CRITICAL9.8Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a configuration search...
CVE-2021-41080CRITICAL9.8Zoho ManageEngine Network Configuration Manager before 125465 is vulnerable to SQL Injection in a hardware details sea...
CVE-2021-43573CRITICAL9.8A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processin...
CVE-2021-33816CRITICAL9.8The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mecha...
CVE-2021-40520CRITICAL9.8Airangel HSMX Gateway devices through 5.2.04 have Weak SSH Credentials.
CVE-2021-3064CRITICAL9.8A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables ...
CVE-2021-40521CRITICAL9.8Airangel HSMX Gateway devices through 5.2.04 allow Remote Code Execution.
CVE-2021-40519CRITICAL10Airangel HSMX Gateway devices through 5.2.04 have Hard-coded Database Credentials.
CVE-2021-43523CRITICAL9.6In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers ...
CVE-2021-43136CRITICAL9.8An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain...
CVE-2021-26443CRITICAL9Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
CVE-2021-43572CRITICAL9.8The verify function in the Stark Bank Python ECDSA library (aka starkbank-escada or ecdsa-python) before 2.0.1 fails to ...
CVE-2021-43571CRITICAL9.8The verify function in the Stark Bank Node.js ECDSA library (ecdsa-node) 1.1.2 fails to check that the signature is non-...
CVE-2021-43570CRITICAL9.8The verify function in the Stark Bank Java ECDSA library (ecdsa-java) 1.0.0 fails to check that the signature is non-zer...
CVE-2021-43569CRITICAL9.8The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-z...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now