2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29629 | HIGH | 7.5 | 1.2% | May 28, 2021 | In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE... |
| CVE-2021-29628 | HIGH | 7.5 | 1.2% | May 28, 2021 | In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE... |
| CVE-2021-33620 | MEDIUM | 6.5 | 79.6% | May 28, 2021 | Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all... |
| CVE-2021-27032 | HIGH | 7.8 | 0.2% | May 28, 2021 | Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited pr... |
| CVE-2021-21734 | MEDIUM | 6.5 | 0.5% | May 28, 2021 | Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by i... |
| CVE-2021-33591 | HIGH | 8.8 | 1.6% | May 28, 2021 | An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary ... |
| CVE-2021-20292 | MEDIUM | 6.7 | 0.9% | May 28, 2021 | There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouvea... |
| CVE-2021-20278 | MEDIUM | 6.5 | 0.8% | May 28, 2021 | An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `Op... |
| CVE-2021-20240 | HIGH | 8.8 | 2.3% | May 28, 2021 | A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can oc... |
| CVE-2021-20239 | LOW | 3.3 | 0.3% | May 28, 2021 | A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a ... |
| CVE-2021-20237 | HIGH | 7.5 | 1.7% | May 28, 2021 | An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. Thi... |
| CVE-2021-20236 | CRITICAL | 9.8 | 1.6% | May 28, 2021 | A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buf... |
| CVE-2021-20201 | MEDIUM | 5.3 | 2.7% | May 28, 2021 | A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a de... |
| CVE-2021-20195 | CRITICAL | 9.6 | 1.2% | May 28, 2021 | A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account... |
| CVE-2021-32543 | MEDIUM | 5.4 | 0.8% | May 28, 2021 | The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote atta... |
| CVE-2021-32542 | MEDIUM | 6.1 | 0.7% | May 28, 2021 | The parameters of the specific functions in the CTS Web trading system do not filter special characters, which allows un... |
| CVE-2021-32541 | MEDIUM | 5.3 | 1.5% | May 28, 2021 | The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows... |
| CVE-2021-32540 | MEDIUM | 5.4 | 0.5% | May 28, 2021 | Add announcement function in the 101EIP system does not filter special characters, which allows authenticated users to i... |
| CVE-2021-32539 | MEDIUM | 5.4 | 0.6% | May 28, 2021 | Add event in calendar function in the 101EIP system does not filter special characters in specific fields, which allows ... |
| CVE-2021-33408 | MEDIUM | 6.5 | 0.7% | May 27, 2021 | Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitr... |
| CVE-2021-27852 | CRITICAL | 9.8 | 31.9% | May 27, 2021 | Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote a... |
| CVE-2021-33394 | MEDIUM | 5.4 | 0.7% | May 27, 2021 | Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged ... |
| CVE-2021-20026 | HIGH | 8.8 | 11.6% | May 27, 2021 | A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection us... |
| CVE-2021-32643 | MEDIUM | 5.8 | 1.4% | May 27, 2021 | Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server whe... |
| CVE-2021-32645 | MEDIUM | 6.1 | 1.0% | May 27, 2021 | Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now