2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-25449CRITICAL9.8An improper input validation vulnerability in libsapeextractor library prior to SMR Sep-2021 Release 1 allows attackers ...
CVE-2021-39296CRITICAL10In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.
CVE-2021-28913CRITICAL9.8BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /webif/SecurityModule to v...
CVE-2021-28911CRITICAL9.8BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers access to /tmp path which contains s...
CVE-2021-28909CRITICAL9.8BAB TECHNOLOGIE GmbH eibPort V3 prior version 3.9.1 allow unauthenticated attackers to access uncontrolled the login ser...
CVE-2021-38727CRITICAL9.8FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
CVE-2021-38540CRITICAL9.8The variable import endpoint was not protected by authentication in Airflow >=2.0.0, <2.1.3. This allowed unauthenticate...
CVE-2021-28495CRITICAL9.8In Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditio...
CVE-2021-26608CRITICAL9.8An arbitrary file download and execution vulnerability was found in the HShell.dll of handysoft Co., Ltd groupware Activ...
CVE-2021-38408CRITICAL9.8A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper va...
CVE-2021-37579CRITICAL9.8The Dubbo Provider will check the incoming request and the corresponding serialization type of this request meet the con...
CVE-2021-36161CRITICAL9.8Some component in Dubbo will try to print the formated string of the input arguments, which will possibly cause RCE for ...
CVE-2021-1946CRITICAL9.8Null Pointer Dereference may occur due to improper validation while processing crafted SDP body in Snapdragon Auto, Snap...
CVE-2021-1933CRITICAL9.8UE assertion is possible due to improper validation of invite message with SDP body in Snapdragon Auto, Snapdragon Compu...
CVE-2021-32835CRITICAL9.9Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti...
CVE-2021-32834CRITICAL9.9Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti...
CVE-2021-40818CRITICAL9.8scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer overflow during FIDO2 signature validation in webaut...
CVE-2021-40814CRITICAL9.8The Customer Photo Gallery addon before 2.9.4 for PrestaShop is vulnerable to SQL injection.
CVE-2021-36440CRITICAL9.8Unrestricted File Upload in ShowDoc v2.9.5 allows remote attackers to execute arbitrary code via the 'file_url' paramete...
CVE-2021-30690CRITICAL9.8Multiple issues in apache were addressed by updating apache to version 2.4.46. This issue is fixed in Security Update 20...
CVE-2021-30678CRITICAL9.8A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.4, Security Update 2...
CVE-2021-30655CRITICAL9.8An application may be able to execute arbitrary code with system privileges. This issue is fixed in macOS Big Sur 11.3, ...
CVE-2021-1882CRITICAL9.8A memory corruption issue was addressed with improved validation. This issue is fixed in Security Update 2021-002 Catali...
CVE-2021-1864CRITICAL9.8A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.5 and iPadOS 14.5, w...
CVE-2021-1834CRITICAL9.8An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.3, Sec...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now