2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-1829CRITICAL9.8A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.3. An applica...
CVE-2021-1770CRITICAL9.8A buffer overflow may result in arbitrary code execution. This issue is fixed in macOS Big Sur 11.3, iOS 14.5 and iPadOS...
CVE-2021-30805CRITICAL9.8A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.5, Secur...
CVE-2021-30793CRITICAL9.8A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.5, Security Update 2...
CVE-2021-1972CRITICAL9.8Possible buffer overflow due to improper validation of device types during P2P search in Snapdragon Auto, Snapdragon Com...
CVE-2021-1920CRITICAL9.8Integer underflow can occur due to improper handling of incoming RTCP packets in Snapdragon Auto, Snapdragon Compute, Sn...
CVE-2021-1919CRITICAL9.8Integer underflow can occur when the RTCP length is lesser than than the actual blocks present in Snapdragon Auto, Snapd...
CVE-2021-1916CRITICAL9.8Possible buffer underflow due to lack of check for negative indices values when processing user provided input in Snapdr...
CVE-2021-32802CRITICAL9.8Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user pro...
CVE-2021-39497CRITICAL9.8eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveR...
CVE-2021-35946CRITICAL9.8A receiver of a federated share with access to the database with ownCloud version before 10.8 could update the permissio...
CVE-2021-40539CRITICAL9.8Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta...
CVE-2021-37716CRITICAL9.8A remote buffer overflow vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating System Soft...
CVE-2021-36163CRITICAL9.8In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and pa...
CVE-2021-38840CRITICAL9.8SQL Injection can occur in Simple Water Refilling Station Management System 1.0 via the water_refilling/classes/Login.ph...
CVE-2021-40540CRITICAL9.8ulfius_uri_logger in Ulfius HTTP Framework before 2.7.4 omits con_info initialization and a con_info->request NULL check...
CVE-2021-40532CRITICAL9.8Telegram Web K Alpha before 0.7.2 mishandles the characters in a document extension.
CVE-2021-40531CRITICAL9.8Sketch before 75 allows library feeds to be used to bypass file quarantine. Files are automatically downloaded and opene...
CVE-2021-3766CRITICAL9.8objection.js is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-40494CRITICAL9.8A Hardcoded JWT Secret Key in metadata.py in AdaptiveScale LXDUI through 2.1.3 allows attackers to gain admin access to ...
CVE-2021-34436CRITICAL9.8In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) v...
CVE-2021-22704CRITICAL9.1A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Confi...
CVE-2021-3757CRITICAL9.8immer is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-34746CRITICAL9.8A vulnerability in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco Enterprise NFV Infras...
CVE-2021-39185CRITICAL9.1Http4s is a minimal, idiomatic Scala interface for HTTP services. In http4s versions 0.21.26 and prior, 0.22.0 through 0...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now