2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31642MEDIUM6.5A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including B...
CVE-2021-31641MEDIUM6.1An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-...
CVE-2021-3543MEDIUM6.7A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closur...
CVE-2021-3516HIGH7.8There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be pr...
CVE-2021-3515MEDIUM6.7A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB priv...
CVE-2021-3495HIGH8.8An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw ...
CVE-2021-3412HIGH7.3It was found that all versions of 3Scale developer portal lacked brute force protections. An attacker could use this gap...
CVE-2021-33184HIGH7.7Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15...
CVE-2021-33183HIGH7.9Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management...
CVE-2021-33182MEDIUM4.3Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in PDF Viewer component in ...
CVE-2021-33181CRITICAL9.1Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows...
CVE-2021-33180CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in S...
CVE-2021-32647CRITICAL9.1Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication...
CVE-2021-32027HIGH8.8A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While...
CVE-2021-30181CRITICAL9.8Apache Dubbo prior to 2.6.9 and 2.7.9 supports Script routing which will enable a customer to route the request to the r...
CVE-2021-30180CRITICAL9.8Apache Dubbo prior to 2.7.9 support Tag routing which will enable a customer to route the request to the right server. T...
CVE-2021-30179CRITICAL9.8Apache Dubbo prior to 2.6.9 and 2.7.9 by default supports generic calls to arbitrary methods exposed by provider interfa...
CVE-2021-29740HIGH7.8IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.3 system core component is affected by a format string ...
CVE-2021-29665HIGH7.8IBM Security Verify Access 20.07 is vulnerable to a stack based buffer overflow, caused by improper bounds checking whic...
CVE-2021-29092HIGH8.8Unrestricted upload of file with dangerous type vulnerability in file management component in Synology Photo Station bef...
CVE-2021-29088HIGH7.8Improper limitation of a pathname to a restricted directory ('Path Traversal') in cgi component in Synology DiskStation ...
CVE-2021-25641CRITICAL9.8Each Apache Dubbo server will set a serialization id to tell the clients which serialization protocol it is working on. ...
CVE-2021-25640MEDIUM6.1In Apache Dubbo prior to 2.6.9 and 2.7.9, the usage of parseURL method will lead to the bypass of white host check which...
CVE-2021-24335MEDIUM6.1The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey sear...
CVE-2021-24334MEDIUM5.4The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise i...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now