2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23401MEDIUM6.1This affects all versions of package Flask-User. When using the make_safe_url function, it is possible to bypass URL val...
CVE-2021-33192MEDIUM6.1A vulnerability in the HTML pages of Apache Jena Fuseki allows an attacker to execute arbitrary javascript on certain pa...
CVE-2021-36148HIGH7.8An issue was discovered in ACRN before 2.5. dmar_free_irte in hypervisor/arch/x86/vtd.c allows an irte_alloc_bitmap buff...
CVE-2021-36147HIGH7.5An issue was discovered in ACRN before 2.5. It allows a devicemodel/hw/pci/virtio/virtio_net.c virtio_net_ping_rxq NULL ...
CVE-2021-36146HIGH7.5ACRN before 2.5 has a devicemodel/hw/pci/xhci.c NULL Pointer Dereference for a trb pointer.
CVE-2021-36145HIGH7.5The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.
CVE-2021-36144HIGH7.5The polling timer handler in ACRN before 2.5 has a use-after-free for a freed virtio device, related to devicemodel/hw/p...
CVE-2021-36143HIGH7.5ACRN before 2.5 has a hw/pci/virtio/virtio.c vq_endchains NULL Pointer Dereference.
CVE-2021-34527HIGH8.8A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file ...
CVE-2021-35209CRITICAL9.8An issue was discovered in ProxyServlet.java in the /proxy servlet in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch...
CVE-2021-35208MEDIUM5.4An issue was discovered in ZmMailMsgView.js in the Calendar Invite component in Zimbra Collaboration Suite 8.8.x before ...
CVE-2021-35207MEDIUM6.1An issue was discovered in Zimbra Collaboration Suite 8.8 before 8.8.15 Patch 23 and 9.0 before 9.0.0 Patch 16. An XSS v...
CVE-2021-34807MEDIUM6.1An open redirect vulnerability exists in the /preauth Servlet in Zimbra Collaboration Suite through 9.0. To exploit the ...
CVE-2021-33889MEDIUM6.8OpenThread wpantund through 2021-07-02 has a stack-based Buffer Overflow because of an inconsistency in the integer data...
CVE-2021-32738MEDIUM6.5js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` func...
CVE-2021-30557HIGH8.8Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install ...
CVE-2021-30556HIGH8.8Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap...
CVE-2021-30555HIGH8.8Use after free in Sharing in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a ...
CVE-2021-30554HIGH8.8Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap co...
CVE-2021-32737MEDIUM4.8Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41...
CVE-2021-31874MEDIUM5.9Zoho ManageEngine ADSelfService Plus before 6104, in rare situations, allows attackers to obtain sensitive information a...
CVE-2021-23403CRITICAL9.8All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validati...
CVE-2021-32639CRITICAL9.9Emissary is a P2P-based, data-driven workflow engine. Emissary version 6.4.0 is vulnerable to Server-Side Request Forger...
CVE-2021-23402CRITICAL9.8All versions of package record-like-deep-assign are vulnerable to Prototype Pollution via the main functionality.
CVE-2021-32735MEDIUM5.4Kirby is a content management system. In Kirby CMS versions 3.5.5 and 3.5.6, the Panel's `ListItem` component (used in t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now