2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-33323HIGH7.5The Dynamic Data Mapping module in Liferay Portal 7.1.0 through 7.3.2, and Liferay DXP 7.1 before fix pack 19, and 7.2 b...
CVE-2021-33322HIGH7.5In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix ...
CVE-2021-33321HIGH7.5Insecure default configuration in Liferay Portal 6.2.3 through 7.3.2, and Liferay DXP before 7.3, allows remote attacker...
CVE-2021-33320MEDIUM4.3The Flags module in Liferay Portal 7.3.1 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20, an...
CVE-2021-32804HIGH8.1The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overw...
CVE-2021-32803HIGH8.1The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Over...
CVE-2021-30564HIGH8.8Heap buffer overflow in WebXR in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit h...
CVE-2021-30563HIGH8.8Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corru...
CVE-2021-30562HIGH8.8Use after free in WebSerial in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit hea...
CVE-2021-30561HIGH8.8Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corru...
CVE-2021-30560HIGH8.8Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit he...
CVE-2021-30559HIGH8.8Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit he...
CVE-2021-30541HIGH8.8Use after free in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corru...
CVE-2021-36654MEDIUM5.4CMSuno 1.7 is vulnerable to an authenticated stored cross site scripting in modifying the filename parameter (tgo) while...
CVE-2021-36623CRITICAL9.8Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE.
CVE-2021-36622CRITICAL9.8Sourcecodester Online Covid Vaccination Scheduler System 1.0 is affected vulnerable to Arbitrary File Upload. The admin ...
CVE-2021-32018MEDIUM6.5An issue was discovered in JUMP AMS 3.6.0.04.009-2487. The JUMP SOAP API was vulnerable to arbitrary file reading due to...
CVE-2021-32016HIGH8.8An issue was discovered in JUMP AMS 3.6.0.04.009-2487. A JUMP SOAP endpoint permitted the writing of arbitrary files to ...
CVE-2021-27942MEDIUM6.8Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs allow a threat actor to execute arbitrary code from a USB driv...
CVE-2021-22425HIGH7.8A component of the HarmonyOS has a Double Free vulnerability. Local attackers may exploit this vulnerability to cause Ro...
CVE-2021-22424MEDIUM5.5A component of the HarmonyOS has a Kernel Memory Leakage Vulnerability. Local attackers may exploit this vulnerability t...
CVE-2021-22423HIGH7.8A component of the HarmonyOS has a Out-of-bounds Write Vulnerability. Local attackers may exploit this vulnerability to ...
CVE-2021-22422HIGH7.8A component of the HarmonyOS has a Integer Overflow or Wraparound vulnerability. Local attackers may exploit this vulner...
CVE-2021-22421HIGH7.8A component of the HarmonyOS has a Improper Privilege Management vulnerability. Local attackers may exploit this vulnera...
CVE-2021-22420HIGH7.8A component of the HarmonyOS has a External Control of System or Configuration Setting vulnerability. Local attackers ma...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now