2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-42388HIGH8.1Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decomp...
CVE-2021-42387HIGH8.1Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decomp...
CVE-2021-42171HIGH7.2Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-s...
CVE-2021-24959HIGH8.8The WP Email Users WordPress plugin through 1.7.6 does not escape the data_raw parameter in the weu_selected_users_1 AJA...
CVE-2021-45886HIGH8.8An issue was discovered in PONTON X/P Messenger before 3.11.2. Anti-CSRF tokens are globally valid, making the web appli...
CVE-2021-42577HIGH7.5An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client ...
CVE-2021-41850HIGH7.8An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a package name of com.skyroa...
CVE-2021-41848HIGH7.8An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It mishandles software updates such that local third-...
CVE-2021-33658HIGH7.8atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune url interface to escalate...
CVE-2021-32476HIGH7.5A denial-of-service risk was identified in the draft files area, due to it not respecting user file upload limits. Moodl...
CVE-2021-32474HIGH7.2An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer hos...
CVE-2021-23246HIGH7.5In ACE2 ColorOS11, the attacker can obtain the foreground package name through permission promotion, resulting in user i...
CVE-2021-39022HIGH8.8IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a Comma-Separated Value (CSV...
CVE-2021-44673HIGH8.8A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malic...
CVE-2021-46408HIGH7.5Tenda AX12 v22.03.01.21 was discovered to contain a stack buffer overflow in the function sub_422CE4. This vulnerability...
CVE-2021-44750HIGH7.3An arbitrary code execution vulnerability was found in the F-Secure Support Tool. A standard user can craft a special co...
CVE-2021-44032HIGH7.5TP-Link Omada SDN Software Controller before 5.0.15 does not check if the authentication method specified in a connectio...
CVE-2021-43970HIGH8.8An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp f...
CVE-2021-42855HIGH7.8It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the ".debug_command.config" file ...
CVE-2021-40376HIGH7.8otris Update Manager 1.2.1.0 allows local users to achieve SYSTEM access via unauthenticated calls to exposed interfaces...
CVE-2021-40064HIGH7.5There is a heap-based buffer overflow vulnerability in system components. Successful exploitation of this vulnerability ...
CVE-2021-40063HIGH7.5There is an improper access control vulnerability in the video module. Successful exploitation of this vulnerability may...
CVE-2021-40062HIGH7.5There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitati...
CVE-2021-40061HIGH7.5There is a vulnerability of accessing resources using an incompatible type (type confusion) in the Bastet module. Succes...
CVE-2021-40060HIGH7.5There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerabilit...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now