2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21005HIGH7.5In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet wi...
CVE-2021-21004MEDIUM6.1In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP fr...
CVE-2021-21003MEDIUM5.3In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Serv...
CVE-2021-21002HIGH7.5In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denia...
CVE-2021-29677MEDIUM5.4IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to cross-site scripting. This vulnerabil...
CVE-2021-29676MEDIUM5.4IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victi...
CVE-2021-20583MEDIUM4.9IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP G...
CVE-2021-32702MEDIUM6.1The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and inc...
CVE-2021-3314MEDIUM6.1Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an adm...
CVE-2021-35501MEDIUM5.4PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an admini...
CVE-2021-34074CRITICAL9.8PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass t...
CVE-2021-34185HIGH7.8Miniaudio 0.10.35 has an integer-based buffer overflow caused by an out-of-bounds left shift in drwav_bytes_to_u32 in mi...
CVE-2021-34184CRITICAL9.8Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in m...
CVE-2021-34183Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-33895HIGH8.1ETINET BACKBOX E4.09 and H4.09 mismanages password access control. When a user uses the User ID of the process running B...
CVE-2021-27043HIGH7.8An Arbitrary Address Write issue in the Autodesk DWG application can allow a malicious user to leverage the application ...
CVE-2021-27042HIGH7.8A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. The vulnerabili...
CVE-2021-27041HIGH7.8A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerabil...
CVE-2021-27040LOW3.3A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnera...
CVE-2021-35050HIGH7.5User credentials stored in a recoverable format within Fidelis Network and Deception CommandPost. In the event that an a...
CVE-2021-35049HIGH8.8Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web inter...
CVE-2021-35048CRITICAL9.8Vulnerability in Fidelis Network and Deception CommandPost enables unauthenticated SQL injection through the web interfa...
CVE-2021-35047HIGH8.8Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker ...
CVE-2021-31615MEDIUM5.3Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent ...
CVE-2021-28958CRITICAL9.8Zoho ManageEngine ADSelfService Plus through 6101 is vulnerable to unauthenticated Remote Code Execution while changing ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now