2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26199MEDIUM6.5An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file...
CVE-2021-26198MEDIUM6.5An issue was discovered in JerryScript 2.4.0. There is a SEVG in ecma_deref_bigint in ecma-helpers.c file.
CVE-2021-26197MEDIUM6.5An issue was discovered in JerryScript 2.4.0. There is a SEGV in main_print_unhandled_exception in main-utils.c file.
CVE-2021-26195HIGH8.8An issue was discovered in JerryScript 2.4.0. There is a heap-buffer-overflow in lexer_parse_number in js-lexer.c file.
CVE-2021-26194MEDIUM6.5An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_is_lexical_environment in the ecma-...
CVE-2021-31840HIGH7.3A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7....
CVE-2021-31839LOW3.3Improper privilege management vulnerability in McAfee Agent for Windows prior to 5.7.3 allows a local user to modify eve...
CVE-2021-20329MEDIUM6.5Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A ...
CVE-2021-34557MEDIUM4.6XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in up...
CVE-2021-34546MEDIUM6.8An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre...
CVE-2021-33031LOW3.1In LabCup before <v2_next_18022, it is possible to use the save API to perform unauthorized actions for users without ac...
CVE-2021-27347MEDIUM5.5Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (D...
CVE-2021-27345MEDIUM5.5A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a de...
CVE-2021-23022HIGH7.8On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's ...
CVE-2021-34555HIGH7.5OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and applicati...
CVE-2021-34547MEDIUM4.3PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation.
CVE-2021-31928HIGH8.8Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadm...
CVE-2021-31927MEDIUM4.3An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows a...
CVE-2021-31659HIGH8.8TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). Al...
CVE-2021-31658HIGH8.1TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface tha...
CVE-2021-31538HIGH7.5LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal.
CVE-2021-23024HIGH7.2On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated rem...
CVE-2021-23023HIGH7.8On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll in...
CVE-2021-21666MEDIUM6.1Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpo...
CVE-2021-21665HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attack...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now