2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29730HIGH8.8IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQ...
CVE-2021-29712MEDIUM6.1IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2021-33012HIGH8.6Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted c...
CVE-2021-27039HIGH7.8A maliciously crafted TIFF and PCX file can be forced to read and write beyond allocated boundaries when parsing the TIF...
CVE-2021-27038HIGH7.8A Type Confusion vulnerability in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can occur when processing a malici...
CVE-2021-27037HIGH7.8A maliciously crafted PNG, PDF or DWF file in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be used to attempt...
CVE-2021-27036HIGH7.8A maliciously crafted PCX, PICT, RCL, TIF, BMP, PSD or TIFF file can be used to write beyond the allocated buffer while ...
CVE-2021-27035HIGH7.8A maliciously crafted TIFF, TIF, PICT, TGA, or DWF files in Autodesk Design Review 2018, 2017, 2013, 2012, 2011 can be f...
CVE-2021-27034HIGH7.8A heap-based buffer overflow could occur while parsing PICT, PCX, RCL or TIFF files in Autodesk Design Review 2018, 2017...
CVE-2021-27033HIGH8.1A maliciously crafted PDF file, when opened by a user in Autodesk Design Review, can trigger a Double Free vulnerability...
CVE-2021-32752MEDIUM4.9Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found ...
CVE-2021-32742CRITICAL9.1Vapor is a web framework for Swift. In versions 4.47.1 and prior, bug in the `Data.init(base32Encoded:)` function opens ...
CVE-2021-30201HIGH7.5The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are...
CVE-2021-30121MEDIUM6.5Semi-authenticated local file inclusion The contents of arbitrary files can be returned by the webserver Example request...
CVE-2021-30120HIGH7.5Kaseya VSA before 9.5.7 allows attackers to bypass the 2FA requirement. The need to use 2FA for authentication in enforc...
CVE-2021-30119MEDIUM5.4Authenticated reflective XSS in HelpDeskTab/rcResults.asp The parameter result of /HelpDeskTab/rcResults.asp is insecure...
CVE-2021-30118CRITICAL9.8An attacker can upload files with the privilege of the Web Server process for Kaseya VSA Unified Remote Monitoring & Man...
CVE-2021-30117HIGH8.8The API call /InstallTab/exportFldr.asp is vulnerable to a semi-authenticated boolean-based blind SQL injection in the p...
CVE-2021-30116CRITICAL9.8Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on pr...
CVE-2021-23405HIGH8.8This affects the package pimcore/pimcore before 10.0.7. This issue exists due to the absence of check on the storeId par...
CVE-2021-36155HIGH7.5LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote a...
CVE-2021-36154HIGH7.5HTTP2ToRawGRPCServerCodec in gRPC Swift 1.1.1 and earlier allows remote attackers to deny service via the delivery of ma...
CVE-2021-36153HIGH7.5Mismanaged state in GRPCWebToHTTP2ServerCodec.swift in gRPC Swift 1.1.0 and 1.1.1 allows remote attackers to deny servic...
CVE-2021-3637HIGH7.5A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in Roo...
CVE-2021-3612HIGH7.8An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now