2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22913MEDIUM6.5Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utiliz...
CVE-2021-22912MEDIUM6.5Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lo...
CVE-2021-22906MEDIUM6.5Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to perm...
CVE-2021-22905MEDIUM6.5Nextcloud Android App (com.nextcloud.client) before v3.16.0 is vulnerable to information disclosure due to searches for ...
CVE-2021-22904HIGH7.5The actionpack ruby gem before 6.1.3.2, 6.0.3.7, 5.2.4.6, 5.2.6 suffers from a possible denial of service vulnerability ...
CVE-2021-22903MEDIUM6.1The actionpack ruby gem before 6.1.3.2 suffers from a possible open redirect vulnerability. Specially crafted Host heade...
CVE-2021-22902HIGH7.5The actionpack ruby gem (a framework for handling and responding to web requests in Rails) before 6.0.3.7, 6.1.3.2 suffe...
CVE-2021-22901HIGH8.1curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when...
CVE-2021-22898LOW3.1curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELN...
CVE-2021-22897MEDIUM5.3curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLO...
CVE-2021-22896MEDIUM4.3Nextcloud Mail before 1.9.5 suffers from improper access control due to a missing permission check allowing other authen...
CVE-2021-22895MEDIUM5.9Nextcloud Desktop Client before 3.3.1 is vulnerable to improper certificate validation due to lack of SSL certificate ve...
CVE-2021-22769MEDIUM4.3A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1...
CVE-2021-22768CRITICAL9.8A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ...
CVE-2021-22767CRITICAL9.8A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ...
CVE-2021-22766HIGH7.5A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ...
CVE-2021-22765CRITICAL9.8A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ...
CVE-2021-22764MEDIUM5.3A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and P...
CVE-2021-22763CRITICAL9.8A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic...
CVE-2021-22762HIGH7.8A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V...
CVE-2021-22761HIGH7.8A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists inIGSS Definitio...
CVE-2021-22760HIGH7.8A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and pr...
CVE-2021-22759HIGH7.8A CWE-416: Use after free vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in ...
CVE-2021-22758HIGH7.8A CWE-824: Access of uninitialized pointer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that...
CVE-2021-22757HIGH7.8A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now