2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1829 | CRITICAL | 9.8 | 2.2% | Sep 8, 2021 | A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.3. An applica... |
| CVE-2021-1770 | CRITICAL | 9.8 | 2.7% | Sep 8, 2021 | A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS... |
| CVE-2021-30805 | CRITICAL | 9.8 | 3.0% | Sep 8, 2021 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Secur... |
| CVE-2021-30793 | CRITICAL | 9.8 | 3.0% | Sep 8, 2021 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.5, Security Update 2... |
| CVE-2021-1972 | CRITICAL | 9.8 | 0.8% | Sep 8, 2021 | Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Com... |
| CVE-2021-1920 | CRITICAL | 9.8 | 0.8% | Sep 8, 2021 | Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Sn... |
| CVE-2021-1919 | CRITICAL | 9.8 | 0.8% | Sep 8, 2021 | Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapd... |
| CVE-2021-1916 | CRITICAL | 9.8 | 0.8% | Sep 8, 2021 | Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdr... |
| CVE-2021-32802 | CRITICAL | 9.8 | 2.5% | Sep 7, 2021 | Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user pro... |
| CVE-2021-39497 | CRITICAL | 9.8 | 2.3% | Sep 7, 2021 | eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveR... |
| CVE-2021-35946 | CRITICAL | 9.8 | 1.4% | Sep 7, 2021 | A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissio... |
| CVE-2021-40539 | CRITICAL | 9.8 | 99.0% | Sep 7, 2021 | Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta... |
| CVE-2021-37716 | CRITICAL | 9.8 | 2.3% | Sep 7, 2021 | A remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Soft... |
| CVE-2021-36163 | CRITICAL | 9.8 | 2.8% | Sep 7, 2021 | In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and pa... |
| CVE-2021-38840 | CRITICAL | 9.8 | 2.5% | Sep 7, 2021 | SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.ph... |
| CVE-2021-40540 | CRITICAL | 9.8 | 2.5% | Sep 7, 2021 | ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check... |
| CVE-2021-40532 | CRITICAL | 9.8 | 1.1% | Sep 6, 2021 | Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension. |
| CVE-2021-40531 | CRITICAL | 9.8 | 32.8% | Sep 6, 2021 | Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opene... |
| CVE-2021-3766 | CRITICAL | 9.8 | 1.4% | Sep 6, 2021 | objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-40494 | CRITICAL | 9.8 | 1.6% | Sep 3, 2021 | A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to ... |
| CVE-2021-34436 | CRITICAL | 9.8 | 2.2% | Sep 2, 2021 | In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) v... |
| CVE-2021-22704 | CRITICAL | 9.1 | 1.2% | Sep 2, 2021 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Confi... |
| CVE-2021-3757 | CRITICAL | 9.8 | 1.6% | Sep 2, 2021 | immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-34746 | CRITICAL | 9.8 | 17.7% | Sep 2, 2021 | A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infras... |
| CVE-2021-39185 | CRITICAL | 9.1 | 0.6% | Sep 1, 2021 | Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now