2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22909HIGH7.5A vulnerability found in EdgeMAX EdgeRouter V2.0.9 and earlier could allow a malicious actor to execute a man-in-the-mid...
CVE-2021-22908HIGH8.8A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with ...
CVE-2021-22907HIGH7.8An improper access control vulnerability exists in Citrix Workspace App for Windows potentially allows privilege escalat...
CVE-2021-22900HIGH7.2A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an auth...
CVE-2021-22899HIGH8.8A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker ...
CVE-2021-22894HIGH8.8A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to...
CVE-2021-22892HIGH7.5An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed ema...
CVE-2021-22891CRITICAL9.8A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5....
CVE-2021-22885HIGH7.5A possible information disclosure / unintended method execution vulnerability in Action Pack >= 2.0.0 when using the `re...
CVE-2021-33590CRITICAL9.8GattLib 0.3-rc1 has a stack-based buffer over-read in get_device_path_from_mac in dbus/gattlib.c.
CVE-2021-33558HIGH7.5Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, previe...
CVE-2021-32459MEDIUM6.5Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log co...
CVE-2021-32458HIGH7.8Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vuln...
CVE-2021-20727MEDIUM6.1Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by l...
CVE-2021-33586MEDIUM4.3InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocate...
CVE-2021-31920MEDIUM6.5Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multi...
CVE-2021-3509MEDIUM6.1A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was...
CVE-2021-30501MEDIUM5.5An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to ca...
CVE-2021-30500HIGH7.8Null pointer dereference was found in upx PackLinuxElf::canUnpack() in p_lx_elf.cpp,in version UPX 4.0.0. That allow att...
CVE-2021-30499HIGH7.8A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and ...
CVE-2021-3561HIGH7.1An Out of Bounds flaw was found fig2dev version 3.2.8a. A flawed bounds check in read_objects() could allow an attacker ...
CVE-2021-3527MEDIUM5.5A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large t...
CVE-2021-3486MEDIUM6.1GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.
CVE-2021-32614HIGH7.1A flaw was found in dmg2img through 20170502. fill_mishblk() does not check the length of the read buffer, and copy 0xCC...
CVE-2021-30498HIGH7.8A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now