2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-26620HIGH7.5An improper authentication vulnerability leading to information leakage was discovered in iptime NAS2dual. Remote attack...
CVE-2021-43091HIGH7.5An SQL Injection vlnerability exits in Yeswiki doryphore 20211012 via the email parameter in the registration form.
CVE-2021-43666HIGH7.5A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an...
CVE-2021-44226HIGH7.3Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Servi...
CVE-2021-28278HIGH7.8A Heap-based Buffer Overflow vulnerability exists in jhead 3.04 and 3.05 via the RemoveSectionType function in jpgfile.c...
CVE-2021-28277HIGH7.8A Heap-based Buffer Overflow vulnerabilty exists in jhead 3.04 and 3.05 is affected by: Buffer Overflow via the RemoveUn...
CVE-2021-28276HIGH7.5A Denial of Service vulnerability exists in jhead 3.04 and 3.05 via a wild address read in the ProcessCanonMakerNoteDir ...
CVE-2021-4197HIGH7.8An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found i...
CVE-2021-4156HIGH7.1An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a speci...
CVE-2021-3748HIGH7.5A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address ...
CVE-2021-3618HIGH7.4ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocol...
CVE-2021-3589HIGH8An authorization flaw was found in Foreman Ansible. An authenticated attacker with certain permissions to create and run...
CVE-2021-27475HIGH8.6Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserializ...
CVE-2021-27474HIGH7.5Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS ...
CVE-2021-27473HIGH8.2Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccw...
CVE-2021-27471HIGH8.6The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may all...
CVE-2021-27422HIGH7.5GE UR firmware versions prior to version 8.1x web server interface is supported on UR over HTTP protocol. It allows sens...
CVE-2021-38772HIGH7.5Tenda AC10-1200 v15.03.06.23_EN was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBi...
CVE-2021-46064HIGH7.8IrfanView 4.59 is vulnerable to buffer overflow via the function at address 0x413c70 (in 32bit version of the binary). T...
CVE-2021-44139HIGH7.5Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF).
CVE-2021-43738HIGH8.8An issue was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can that can add the administrat...
CVE-2021-44759HIGH8.1Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a m...
CVE-2021-44040HIGH7.5Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows an attacker to send inva...
CVE-2021-45757HIGH7.5ASUS AC68U <=3.0.0.4.385.20852 is affected by a buffer overflow in blocking.cgi, which may cause a denial of service (Do...
CVE-2021-45810HIGH7.5GlobalProtect-openconnect versions prior to 2.0.0 (exclusive) are affected by incorrect access control in GPService thro...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now