2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23017HIGH7.7A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t...
CVE-2021-27828CRITICAL9.1SQL injection in In4Suite ERP 3.2.74.1370 allows attackers to modify or delete data, causing persistent changes to the a...
CVE-2021-25932MEDIUM5.4In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation...
CVE-2021-23018HIGH7.4Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are us...
CVE-2021-33790CRITICAL9.8The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputSt...
CVE-2021-33564CRITICAL9.8An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write...
CVE-2021-31703CRITICAL9.8Frontier ichris through 5.18 allows users to upload malicious executable files that might later be downloaded and run by...
CVE-2021-31702HIGH7.5Frontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated b...
CVE-2021-30461CRITICAL9.8A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,...
CVE-2021-32635MEDIUM6.3Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `si...
CVE-2021-32621HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions pri...
CVE-2021-32620HIGH8.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions pri...
CVE-2021-32619CRITICAL9.8Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, mod...
CVE-2021-32616MEDIUM6.11CDN is open-source file sharing software. In 1CDN before commit f88a2730fa50fc2c2aeab09011f6f142fd90ec25, there is a ba...
CVE-2021-29507MEDIUM6.5GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2...
CVE-2021-29505HIGH8.8XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4...
CVE-2021-29492HIGH8.3Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP...
CVE-2021-33587HIGH7.5The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity r...
CVE-2021-22519CRITICAL9.8Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40,11.41 , 2018.05(11.50), ...
CVE-2021-20267HIGH7.1A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyon...
CVE-2021-33623HIGH7.5The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denia...
CVE-2021-32646HIGH7.3Roomer is a discord bot cog (extension) which provides automatic voice channel generation as well as private voice and t...
CVE-2021-32642CRITICAL9.4radsecproxy is a generic RADIUS proxy that supports both UDP and TLS (RadSec) RADIUS transports. Missing input validatio...
CVE-2021-32637CRITICAL10Authelia is a a single sign-on multi-factor portal for web apps. This affects uses who are using nginx ngx_http_auth_req...
CVE-2021-3514MEDIUM6.5When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a spe...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now