2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29629HIGH7.5In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE...
CVE-2021-29628HIGH7.5In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE...
CVE-2021-33620MEDIUM6.5Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all...
CVE-2021-27032HIGH7.8Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited pr...
CVE-2021-21734MEDIUM6.5Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by i...
CVE-2021-33591HIGH8.8An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary ...
CVE-2021-20292MEDIUM6.7There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouvea...
CVE-2021-20278MEDIUM6.5An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `Op...
CVE-2021-20240HIGH8.8A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can oc...
CVE-2021-20239LOW3.3A flaw was found in the Linux kernel in versions before 5.4.92 in the BPF protocol. This flaw allows an attacker with a ...
CVE-2021-20237HIGH7.5An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. Thi...
CVE-2021-20236CRITICAL9.8A flaw was found in the ZeroMQ server in versions before 4.3.3. This flaw allows a malicious client to cause a stack buf...
CVE-2021-20201MEDIUM5.3A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a de...
CVE-2021-20195CRITICAL9.6A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account...
CVE-2021-32543MEDIUM5.4The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote atta...
CVE-2021-32542MEDIUM6.1The parameters of the specific functions in the CTS Web trading system do not filter special characters, which allows un...
CVE-2021-32541MEDIUM5.3The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows...
CVE-2021-32540MEDIUM5.4Add announcement function in the 101EIP system does not filter special characters, which allows authenticated users to i...
CVE-2021-32539MEDIUM5.4Add event in calendar function in the 101EIP system does not filter special characters in specific fields, which allows ...
CVE-2021-33408MEDIUM6.5Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitr...
CVE-2021-27852CRITICAL9.8Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote a...
CVE-2021-33394MEDIUM5.4Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged ...
CVE-2021-20026HIGH8.8A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection us...
CVE-2021-32643MEDIUM5.8Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server whe...
CVE-2021-32645MEDIUM6.1Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now