2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-40058HIGH7.5There is a heap-based buffer overflow vulnerability in the video framework. Successful exploitation of this vulnerabilit...
CVE-2021-40057HIGH7.5There is a heap-based and stack-based buffer overflow vulnerability in the video framework. Successful exploitation of t...
CVE-2021-40056HIGH7.5There is a vulnerability of copying input buffer without checking its size in the video framework. Successful exploitati...
CVE-2021-40054HIGH7.5There is an integer underflow vulnerability in the atcmdserver module. Successful exploitation of this vulnerability may...
CVE-2021-40052HIGH7.5There is an incorrect buffer size calculation vulnerability in the video framework.Successful exploitation of this vulne...
CVE-2021-40051HIGH7.5There is an unauthorized access vulnerability in system components. Successful exploitation of this vulnerability will a...
CVE-2021-40049HIGH7.5There is a permission control vulnerability in the PMS module. Successful exploitation of this vulnerability can lead to...
CVE-2021-40048HIGH7.5There is an incorrect buffer size calculation vulnerability in the video framework. Successful exploitation of this vuln...
CVE-2021-40047HIGH7.5There is a vulnerability of memory not being released after effective lifetime in the Bastet module. Successful exploita...
CVE-2021-3739HIGH7.1A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, whe...
CVE-2021-3698HIGH7.5A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the...
CVE-2021-32025HIGH7.8An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Plat...
CVE-2021-38296HIGH7.5Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enable...
CVE-2021-22783HIGH7.6A CWE-200: Information Exposure vulnerability exists which could allow a session hijack when the door panel is communica...
CVE-2021-36777HIGH8.8A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service all...
CVE-2021-42020HIGH7.5A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i80...
CVE-2021-42016HIGH7.5A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, ...
CVE-2021-43944HIGH7.2This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has ...
CVE-2021-4199HIGH7.8Incorrect Permission Assignment for Critical Resource vulnerability in the crash handling component BDReinit.exe as used...
CVE-2021-25087HIGH7.5The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpo...
CVE-2021-24952HIGH8.8The Conversios.io WordPress plugin before 4.6.2 does not sanitise, validate and escape the sync_progressive_data paramet...
CVE-2021-24778HIGH7.2The test parameter of the xmlfeed in the Tradetracker-Store WordPress plugin before 4.6.60 is not sanitised, escaped or ...
CVE-2021-24777HIGH7.2The view submission functionality in the Hotscot Contact Form WordPress plugin before 1.3 makes a get request with the s...
CVE-2021-24216HIGH7.2The All-in-One WP Migration WordPress plugin before 7.41 does not validate uploaded files' extension, which allows admin...
CVE-2021-44827HIGH8.8There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now