2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0558MEDIUM6.5In fillMainDataBuf of pvmp3_framedecoder.cpp, there is a possible out of bounds read due to a heap buffer overflow. This...
CVE-2021-0557HIGH8.8In setRange of ABuffer.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remot...
CVE-2021-0556MEDIUM5.5In getBlockSum of fastcodemb.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead ...
CVE-2021-0555HIGH7.5In RenderStruct of protostream_objectsource.cc, there is a possible crash due to a missing null check. This could lead t...
CVE-2021-0554MEDIUM5.5In isBackupServiceActive of BackupManagerService.java, there is a missing permission check. This could lead to local inf...
CVE-2021-0535MEDIUM6.7In wpas_ctrl_msg_queue_timeout of ctrl_iface_unix.c, there is a possible memory corruption due to a use after free. This...
CVE-2021-0534HIGH7.8In permission declarations of DeviceAdminReceiver.java, there is a possible lack of broadcast protection due to an insec...
CVE-2021-20744MEDIUM6.1Cross-site scripting vulnerability in EC-CUBE Category contents plugin (for EC-CUBE 3.0 series) versions prior to versio...
CVE-2021-20743MEDIUM6.1Cross-site scripting vulnerability in EC-CUBE Email newsletters management plugin (for EC-CUBE 3.0 series) versions prio...
CVE-2021-20742MEDIUM6.1Cross-site scripting vulnerability in EC-CUBE Business form output plugin (for EC-CUBE 3.0 series) versions prior to ver...
CVE-2021-20741MEDIUM6.1Cross-site scripting vulnerability in Hitachi Application Server Help (Hitachi Application Server V10 Manual (Windows) v...
CVE-2021-20737MEDIUM6.5Improper authentication vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to view the unauthoriz...
CVE-2021-20736CRITICAL9.1NoSQL injection vulnerability in GROWI versions prior to v4.2.20 allows a remote attacker to obtain and/or alter the inf...
CVE-2021-20735MEDIUM6.1Cross-site scripting vulnerability in ETUNA EC-CUBE plugins (Delivery slip number plugin (3.0 series) 1.0.10 and earlier...
CVE-2021-20734MEDIUM6.1Cross-site scripting vulnerability in Welcart e-Commerce versions prior to 2.2.4 allows remote attackers to inject arbit...
CVE-2021-20733MEDIUM6.1Improper authorization in handler for custom URL scheme vulnerability in あすけんダイエット (asken diet) for Android versions fro...
CVE-2021-35196HIGH7.8Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a proj...
CVE-2021-34389MEDIUM5Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorre...
CVE-2021-34388HIGH7.8Bootloader contains a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to contr...
CVE-2021-34387MEDIUM6.7The ARM TrustZone Technology on which Trusty is based on contains a vulnerability in access permission settings where th...
CVE-2021-34386MEDIUM6.7Trusty TLK contains a vulnerability in the NVIDIA TLK kernel where an integer overflow in the calloc size calculation ca...
CVE-2021-32698MEDIUM4.9eLabFTW is an open source electronic lab notebook for research labs. This vulnerability allows an attacker to make GET r...
CVE-2021-35066CRITICAL9.8An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
CVE-2021-29063HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpm...
CVE-2021-29061HIGH7.5A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now