2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38171 | CRITICAL | 9.8 | 2.4% | Aug 21, 2021 | adts_decode_extradata in libavformat/adtsenc.c in FFmpeg 4.4 does not check the init_get_bits return value, which is a n... |
| CVE-2021-21828 | CRITICAL | 9.8 | 1.1% | Aug 20, 2021 | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xm... |
| CVE-2021-21827 | CRITICAL | 9.8 | 1.1% | Aug 20, 2021 | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xm... |
| CVE-2021-21826 | CRITICAL | 9.8 | 1.1% | Aug 20, 2021 | A heap-based buffer overflow vulnerability exists in the XML Decompression DecodeTreeBlock functionality of AT&T Labs Xm... |
| CVE-2021-37597 | CRITICAL | 9.8 | 2.1% | Aug 19, 2021 | WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation. |
| CVE-2021-39302 | CRITICAL | 9.8 | 0.9% | Aug 19, 2021 | MISP 2.4.148, in certain configurations, allows SQL injection via the app/Model/Log.php $conditions['org'] value. |
| CVE-2021-39274 | CRITICAL | 9.8 | 3.1% | Aug 19, 2021 | In XeroSecurity Sn1per 9.0 (free version), insecure directory permissions (0777) are set during installation, allowing a... |
| CVE-2021-31226 | CRITICAL | 9.8 | 3.2% | Aug 19, 2021 | An issue was discovered in HCC embedded InterNiche 4.0.1. A potential heap buffer overflow exists in the code that parse... |
| CVE-2021-32588 | CRITICAL | 9.8 | 3.3% | Aug 18, 2021 | A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 ... |
| CVE-2021-34730 | CRITICAL | 9.8 | 13.6% | Aug 18, 2021 | A vulnerability in the Universal Plug-and-Play (UPnP) service of Cisco Small Business RV110W, RV130, RV130W, and RV215W ... |
| CVE-2021-37358 | CRITICAL | 9.8 | 2.3% | Aug 18, 2021 | SQL Injection in SEACMS v210530 (2021-05-30) allows remote attackers to execute arbitrary code via the component "admin_... |
| CVE-2021-21825 | CRITICAL | 9.8 | 2.3% | Aug 18, 2021 | A heap-based buffer overflow vulnerability exists in the XML Decompression PlainTextUncompressor::UncompressItem functio... |
| CVE-2021-37608 | CRITICAL | 9.8 | 6.0% | Aug 18, 2021 | Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz allows an attacker to execute remote comma... |
| CVE-2021-21832 | CRITICAL | 9.8 | 1.2% | Aug 17, 2021 | A memory corruption vulnerability exists in the ISO Parsing functionality of Disc Soft Ltd Deamon Tools Pro 8.3.0.0767. ... |
| CVE-2021-21810 | CRITICAL | 9.8 | 1.1% | Aug 17, 2021 | A memory corruption vulnerability exists in the XML-parsing ParseAttribs functionality of AT&T Labs’ Xmill 0.7. A specia... |
| CVE-2021-22156 | CRITICAL | 9.8 | 1.8% | Aug 17, 2021 | An integer overflow vulnerability in the calloc() function of the C runtime library of affected versions of BlackBerry® ... |
| CVE-2021-3616 | CRITICAL | 9.8 | 0.9% | Aug 17, 2021 | A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device... |
| CVE-2021-32829 | CRITICAL | 9.9 | 2.9% | Aug 17, 2021 | ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of c... |
| CVE-2021-32827 | CRITICAL | 9.6 | 2.2% | Aug 16, 2021 | MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An att... |
| CVE-2021-37708 | CRITICAL | 9.8 | 2.4% | Aug 16, 2021 | Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in ma... |
| CVE-2021-32825 | CRITICAL | 9.1 | 0.9% | Aug 16, 2021 | bblfshd is an open source self-hosted server for source code parsing. In bblfshd before commit 4265465b9b6fb5663c30ee438... |
| CVE-2021-22931 | CRITICAL | 9.8 | 22.0% | Aug 16, 2021 | Node.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to miss... |
| CVE-2021-38754 | CRITICAL | 9.8 | 1.8% | Aug 16, 2021 | SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php. |
| CVE-2021-38753 | CRITICAL | 9.8 | 1.5% | Aug 16, 2021 | An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain ... |
| CVE-2021-35395 | CRITICAL | 9.8 | 98.1% | Aug 16, 2021 | Realtek Jungle SDK version v2.x up to v3.4.14B provides an HTTP web server exposing a management interface that can be u... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now