2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35475 | MEDIUM | 5.4 | 0.9% | Jun 25, 2021 | SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when e... |
| CVE-2021-32717 | HIGH | 7.5 | 1.5% | Jun 24, 2021 | Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 private files publicly accessible with Cloud... |
| CVE-2021-32716 | MEDIUM | 4.9 | 1.1% | Jun 24, 2021 | Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidd... |
| CVE-2021-32713 | MEDIUM | 4.8 | 0.7% | Jun 24, 2021 | Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in admin... |
| CVE-2021-32712 | MEDIUM | 5.3 | 1.1% | Jun 24, 2021 | Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in ... |
| CVE-2021-35448 | HIGH | 7.8 | 1.0% | Jun 24, 2021 | Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using... |
| CVE-2021-32711 | HIGH | 7.5 | 1.4% | Jun 24, 2021 | Shopware is an open source eCommerce platform. Versions prior to 6.3.5.1 may leak of information via Store-API. The vuln... |
| CVE-2021-32710 | HIGH | 7.5 | 0.9% | Jun 24, 2021 | Shopware is an open source eCommerce platform. Potential session hijacking of store customers in versions below 6.3.5.2.... |
| CVE-2021-3500 | HIGH | 7.8 | 0.9% | Jun 24, 2021 | A flaw was found in djvulibre-3.5.28 and earlier. A Stack overflow in function DJVU::DjVuDocument::get_djvu_file() via c... |
| CVE-2021-32709 | MEDIUM | 4.9 | 0.6% | Jun 24, 2021 | Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users... |
| CVE-2021-32493 | HIGH | 7.8 | 1.0% | Jun 24, 2021 | A flaw was found in djvulibre-3.5.28 and earlier. A heap buffer overflow in function DJVU::GBitmap::decode() via crafted... |
| CVE-2021-32492 | HIGH | 7.8 | 0.9% | Jun 24, 2021 | A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds read in function DJVU::DataPool::has_data() via craft... |
| CVE-2021-32491 | HIGH | 7.8 | 0.9% | Jun 24, 2021 | A flaw was found in djvulibre-3.5.28 and earlier. An integer overflow in function render() in tools/ddjvu via crafted dj... |
| CVE-2021-32490 | HIGH | 7.8 | 0.9% | Jun 24, 2021 | A flaw was found in djvulibre-3.5.28 and earlier. An out of bounds write in function DJVU::filter_bv() via crafted djvu ... |
| CVE-2021-29777 | MEDIUM | 6.5 | 1.4% | Jun 24, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circum... |
| CVE-2021-29703 | HIGH | 7.5 | 1.7% | Jun 24, 2021 | Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server termina... |
| CVE-2021-20579 | MEDIUM | 6.5 | 1.1% | Jun 24, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who... |
| CVE-2021-33004 | HIGH | 7.8 | 0.9% | Jun 24, 2021 | The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied file... |
| CVE-2021-33002 | HIGH | 7.8 | 1.0% | Jun 24, 2021 | Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbi... |
| CVE-2021-33000 | HIGH | 7.8 | 1.0% | Jun 24, 2021 | Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perfor... |
| CVE-2021-32708 | HIGH | 8.1 | 3.5% | Jun 24, 2021 | Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any ... |
| CVE-2021-21574 | HIGH | 7.5 | 0.3% | Jun 24, 2021 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local acce... |
| CVE-2021-21573 | HIGH | 7.5 | 0.3% | Jun 24, 2021 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local acce... |
| CVE-2021-21572 | HIGH | 7.5 | 0.3% | Jun 24, 2021 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local acce... |
| CVE-2021-21571 | MEDIUM | 6.5 | 0.6% | Jun 24, 2021 | Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper ce... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now