2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22909 | HIGH | 7.5 | 1.3% | May 27, 2021 | A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-mid... |
| CVE-2021-22908 | HIGH | 8.8 | 69.4% | May 27, 2021 | A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with ... |
| CVE-2021-22907 | HIGH | 7.8 | 0.2% | May 27, 2021 | An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalat... |
| CVE-2021-22900 | HIGH | 7.2 | 14.1% | May 27, 2021 | A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an auth... |
| CVE-2021-22899 | HIGH | 8.8 | 22.3% | May 27, 2021 | A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker ... |
| CVE-2021-22894 | HIGH | 8.8 | 41.3% | May 27, 2021 | A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to... |
| CVE-2021-22892 | HIGH | 7.5 | 1.9% | May 27, 2021 | An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed ema... |
| CVE-2021-22891 | CRITICAL | 9.8 | 1.1% | May 27, 2021 | A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.... |
| CVE-2021-22885 | HIGH | 7.5 | 4.2% | May 27, 2021 | A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `re... |
| CVE-2021-33590 | CRITICAL | 9.8 | 1.5% | May 27, 2021 | GattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c. |
| CVE-2021-33558 | HIGH | 7.5 | 10.3% | May 27, 2021 | Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, previe... |
| CVE-2021-32459 | MEDIUM | 6.5 | 1.0% | May 27, 2021 | Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log co... |
| CVE-2021-32458 | HIGH | 7.8 | 0.4% | May 27, 2021 | Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vuln... |
| CVE-2021-20727 | MEDIUM | 6.1 | 1.0% | May 27, 2021 | Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by l... |
| CVE-2021-33586 | MEDIUM | 4.3 | 0.9% | May 27, 2021 | InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocate... |
| CVE-2021-31920 | MEDIUM | 6.5 | 1.2% | May 27, 2021 | Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multi... |
| CVE-2021-3509 | MEDIUM | 6.1 | 1.7% | May 27, 2021 | A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was... |
| CVE-2021-30501 | MEDIUM | 5.5 | 1.0% | May 27, 2021 | An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to ca... |
| CVE-2021-30500 | HIGH | 7.8 | 1.2% | May 27, 2021 | Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow att... |
| CVE-2021-30499 | HIGH | 7.8 | 1.3% | May 27, 2021 | A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and ... |
| CVE-2021-3561 | HIGH | 7.1 | 1.2% | May 26, 2021 | An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker ... |
| CVE-2021-3527 | MEDIUM | 5.5 | 0.4% | May 26, 2021 | A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large t... |
| CVE-2021-3486 | MEDIUM | 6.1 | 1.4% | May 26, 2021 | GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code. |
| CVE-2021-32614 | HIGH | 7.1 | 0.9% | May 26, 2021 | A flaw was found in dmg2img through 20170502. fill_mishblk() does not check the length of the read buffer, and copy 0xCC... |
| CVE-2021-30498 | HIGH | 7.8 | 1.4% | May 26, 2021 | A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now