2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26199 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_bytecode_ref in ecma-helpers.c file... |
| CVE-2021-26198 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | An issue was discovered in JerryScript 2.4.0. There is a SEVG in ecma_deref_bigint in ecma-helpers.c file. |
| CVE-2021-26197 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | An issue was discovered in JerryScript 2.4.0. There is a SEGV in main_print_unhandled_exception in main-utils.c file. |
| CVE-2021-26195 | HIGH | 8.8 | 1.1% | Jun 10, 2021 | An issue was discovered in JerryScript 2.4.0. There is a heap-buffer-overflow in lexer_parse_number in js-lexer.c file. |
| CVE-2021-26194 | MEDIUM | 6.5 | 0.9% | Jun 10, 2021 | An issue was discovered in JerryScript 2.4.0. There is a heap-use-after-free in ecma_is_lexical_environment in the ecma-... |
| CVE-2021-31840 | HIGH | 7.3 | 0.3% | Jun 10, 2021 | A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.... |
| CVE-2021-31839 | LOW | 3.3 | 0.2% | Jun 10, 2021 | Improper privilege management vulnerability in McAfee Agent for Windows prior to 5.7.3 allows a local user to modify eve... |
| CVE-2021-20329 | MEDIUM | 6.5 | 1.0% | Jun 10, 2021 | Specific cstrings input may not be properly validated in the MongoDB Go Driver when marshalling Go objects into BSON. A ... |
| CVE-2021-34557 | MEDIUM | 4.6 | 0.5% | Jun 10, 2021 | XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in up... |
| CVE-2021-34546 | MEDIUM | 6.8 | 0.7% | Jun 10, 2021 | An unauthenticated attacker with physical access to a computer with NetSetMan Pro before 5.0 installed, that has the pre... |
| CVE-2021-33031 | LOW | 3.1 | 0.7% | Jun 10, 2021 | In LabCup before <v2_next_18022, it is possible to use the save API to perform unauthorized actions for users without ac... |
| CVE-2021-27347 | MEDIUM | 5.5 | 0.7% | Jun 10, 2021 | Use after free in lzma_decompress_buf function in stream.c in Irzip 0.631 allows attackers to cause Denial of Service (D... |
| CVE-2021-27345 | MEDIUM | 5.5 | 0.7% | Jun 10, 2021 | A null pointer dereference was discovered in ucompthread in stream.c in Irzip 0.631 which allows attackers to cause a de... |
| CVE-2021-23022 | HIGH | 7.8 | 0.2% | Jun 10, 2021 | On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, the BIG-IP Edge Client Windows Installer Service's ... |
| CVE-2021-34555 | HIGH | 7.5 | 2.7% | Jun 10, 2021 | OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and applicati... |
| CVE-2021-34547 | MEDIUM | 4.3 | 0.4% | Jun 10, 2021 | PRTG Network Monitor 20.1.55.1775 allows /editsettings CSRF for user account creation. |
| CVE-2021-31928 | HIGH | 8.8 | 1.2% | Jun 10, 2021 | Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to escalate privileges to superadm... |
| CVE-2021-31927 | MEDIUM | 4.3 | 0.5% | Jun 10, 2021 | An Insecure Direct Object Reference (IDOR) vulnerability in Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows a... |
| CVE-2021-31659 | HIGH | 8.8 | 0.6% | Jun 10, 2021 | TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is vulnerable to Cross Site Request Forgery (CSRF). Al... |
| CVE-2021-31658 | HIGH | 8.1 | 1.1% | Jun 10, 2021 | TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface tha... |
| CVE-2021-31538 | HIGH | 7.5 | 1.5% | Jun 10, 2021 | LANCOM R&S Unified Firewall (UF) devices running LCOS FX 10.5 allow Relative Path Traversal. |
| CVE-2021-23024 | HIGH | 7.2 | 5.3% | Jun 10, 2021 | On version 8.0.x before 8.0.0.1, and all 6.x and 7.x versions, the BIG-IQ Configuration utility has an authenticated rem... |
| CVE-2021-23023 | HIGH | 7.8 | 0.3% | Jun 10, 2021 | On version 7.2.1.x before 7.2.1.3 and 7.1.x before 7.1.9.9 Update 1, a DLL hijacking issue exists in cachecleaner.dll in... |
| CVE-2021-21666 | MEDIUM | 6.1 | 1.2% | Jun 10, 2021 | Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpo... |
| CVE-2021-21665 | HIGH | 8.8 | 0.7% | Jun 10, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attack... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now