2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-38266HIGH7.5The Portal Security module in Liferay Portal 7.2.1 and earlier, and Liferay DXP 7.0 before fix pack 90, 7.1 before fix p...
CVE-2021-23206HIGH7.8A flaw was found in htmldoc in v1.9.12 and prior. A stack buffer overflow in parse_table() in ps-pdf.cxx may lead to exe...
CVE-2021-23192HIGH7.5A flaw was found in the way samba implemented DCE/RPC. If a client to a Samba server sent a very large DCE/RPC request, ...
CVE-2021-23191HIGH7.8A security issue was found in htmldoc v1.9.12 and before. A NULL pointer dereference in the function image_load_jpeg() i...
CVE-2021-23180HIGH7.8A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to ex...
CVE-2021-41002HIGH8.1Multiple authenticated remote path traversal vulnerabilities were discovered in the AOS-CX command line interface in Aru...
CVE-2021-41001HIGH8.8An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Arub...
CVE-2021-41000HIGH8.8Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aru...
CVE-2021-41652HIGH7.5Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
CVE-2021-41282HIGH8.8diag_routes.php in pfSense 2.5.2 allows sed data injection. Authenticated users are intended to be able to view data abo...
CVE-2021-43077HIGH8.8A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6....
CVE-2021-43075HIGH8.8A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio...
CVE-2021-36171HIGH8.1The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6...
CVE-2021-44238HIGH7.2AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php,
CVE-2021-43619HIGH7.8Trusted Firmware M 1.4.x through 1.4.1 has a buffer overflow issue in the Firmware Update partition. In the IPC model, a...
CVE-2021-42951HIGH8.8A Remote Code Execution (RCE) vulnerability exists in Algorithmia MSOL all versions before October 10 2021 of SaaS. User...
CVE-2021-41112HIGH8.1Rundeck is an open source automation service with a web console, command line tools and a WebAPI. In versions prior to 3...
CVE-2021-44342HIGH7.8David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow via function ok_png_transform_scanline() in "/ok...
CVE-2021-44331HIGH7.8ARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise().
CVE-2021-44340HIGH7.8David Brackeen ok-file-formats dev version is vulnerable to Buffer Overflow. When the function of the ok-file-formats pr...
CVE-2021-44339HIGH7.8David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats projec...
CVE-2021-44334HIGH7.8David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats projec...
CVE-2021-24864HIGH8.8The WP Cloudy, weather plugin WordPress plugin before 4.4.9 does not escape the post_id parameter before using it in a S...
CVE-2021-24823HIGH8.1The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php...
CVE-2021-24803HIGH8.8The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now