2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-23452CRITICAL9.8This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
CVE-2021-35652CRITICAL10Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported v...
CVE-2021-35617CRITICAL9.8Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Coherence Container). Suppor...
CVE-2021-30304CRITICAL9.1Possible buffer out of bound read can occur due to improper validation of TBTT count and length while parsing the beacon...
CVE-2021-1980CRITICAL9.1Possible buffer over read due to lack of length check while parsing beacon IE response in Snapdragon Auto, Snapdragon Co...
CVE-2021-1977CRITICAL9.1Possible buffer over read due to improper validation of frame length while processing AEAD decryption during ASSOC respo...
CVE-2021-31384CRITICAL10Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuratio...
CVE-2021-31382CRITICAL9On PTX1000 System, PTX10002-60C System, after upgrading to an affected release, a Race Condition vulnerability between t...
CVE-2021-31381CRITICAL9.1A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remo...
CVE-2021-31349CRITICAL9.8The usage of an internal HTTP header created an authentication bypass vulnerability (CWE-287), allowing an attacker to v...
CVE-2021-30820CRITICAL9.8A logic issue was addressed with improved state management. This issue is fixed in iOS 14.8 and iPadOS 14.8. A remote at...
CVE-2021-38478CRITICAL9.1InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute too...
CVE-2021-38474CRITICAL9.8InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 have has no account lockout policy configured for th...
CVE-2021-38470CRITICAL9.1InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to i...
CVE-2021-38462CRITICAL9.8InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 does not enforce an efficient password policy. This ...
CVE-2021-41153CRITICAL9.8The evm crate is a pure Rust implementation of Ethereum Virtual Machine. In `evm` crate `< 0.31.0`, `JUMPI` opcode's con...
CVE-2021-23449CRITICAL10This affects the package vm2 before 3.9.4 via a Prototype Pollution attack vector, which can lead to execution of arbitr...
CVE-2021-42576CRITICAL9.8The bluemonday sanitizer before 1.0.16 for Go, and before 0.0.8 for Python (in pybluemonday), does not properly enforce ...
CVE-2021-42575CRITICAL9.8The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, an...
CVE-2021-38389CRITICAL9.8Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker...
CVE-2021-33023CRITICAL9.8Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker ...
CVE-2021-22961CRITICAL9.8A code injection vulnerability exists within the firewall software of GlassWire v2.1.167 that could lead to arbitrary co...
CVE-2021-38297CRITICAL9.8Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM...
CVE-2021-27561CRITICAL9.8Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, ...
CVE-2021-40997CRITICAL9.8A remote authentication bypass vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Poli...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now