2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29730 | HIGH | 8.8 | 1.0% | Jul 9, 2021 | IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ... |
| CVE-2021-29712 | MEDIUM | 6.1 | 0.7% | Jul 9, 2021 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a... |
| CVE-2021-33012 | HIGH | 8.6 | 1.9% | Jul 9, 2021 | Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted c... |
| CVE-2021-27039 | HIGH | 7.8 | 1.6% | Jul 9, 2021 | A maliciously crafted TIFF and PCX file can be forced to read and write beyond allocated boundaries when parsing the TIF... |
| CVE-2021-27038 | HIGH | 7.8 | 1.8% | Jul 9, 2021 | A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a malici... |
| CVE-2021-27037 | HIGH | 7.8 | 1.6% | Jul 9, 2021 | A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt... |
| CVE-2021-27036 | HIGH | 7.8 | 1.7% | Jul 9, 2021 | A maliciously crafted PCX, PICT, RCL, TIF, BMP, PSD or TIFF file can be used to write beyond the allocated buffer while ... |
| CVE-2021-27035 | HIGH | 7.8 | 1.7% | Jul 9, 2021 | A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be f... |
| CVE-2021-27034 | HIGH | 7.8 | 2.2% | Jul 9, 2021 | A heap-based buffer overflow could occur while parsing PICT, PCX, RCL or TIFF files in Autodesk Design Review 2018, 2017... |
| CVE-2021-27033 | HIGH | 8.1 | 3.0% | Jul 9, 2021 | A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability... |
| CVE-2021-32752 | MEDIUM | 4.9 | 1.1% | Jul 9, 2021 | Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found ... |
| CVE-2021-32742 | CRITICAL | 9.1 | 1.2% | Jul 9, 2021 | Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens ... |
| CVE-2021-30201 | HIGH | 7.5 | 25.3% | Jul 9, 2021 | The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are... |
| CVE-2021-30121 | MEDIUM | 6.5 | 4.8% | Jul 9, 2021 | Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request... |
| CVE-2021-30120 | HIGH | 7.5 | 5.7% | Jul 9, 2021 | Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforc... |
| CVE-2021-30119 | MEDIUM | 5.4 | 52.7% | Jul 9, 2021 | Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecure... |
| CVE-2021-30118 | CRITICAL | 9.8 | 60.1% | Jul 9, 2021 | An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Man... |
| CVE-2021-30117 | HIGH | 8.8 | 72.1% | Jul 9, 2021 | The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the p... |
| CVE-2021-30116 | CRITICAL | 9.8 | 85.7% | Jul 9, 2021 | Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on pr... |
| CVE-2021-23405 | HIGH | 8.8 | 1.7% | Jul 9, 2021 | This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId par... |
| CVE-2021-36155 | HIGH | 7.5 | 2.1% | Jul 9, 2021 | LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote a... |
| CVE-2021-36154 | HIGH | 7.5 | 2.1% | Jul 9, 2021 | HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of ma... |
| CVE-2021-36153 | HIGH | 7.5 | 2.1% | Jul 9, 2021 | Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny servic... |
| CVE-2021-3637 | HIGH | 7.5 | 1.1% | Jul 9, 2021 | A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in Roo... |
| CVE-2021-3612 | HIGH | 7.8 | 0.7% | Jul 9, 2021 | An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now