2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-33525 | HIGH | 8.8 | 7.7% | May 24, 2021 | EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in... |
| CVE-2021-30108 | CRITICAL | 9.1 | 1.1% | May 24, 2021 | Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Refer... |
| CVE-2021-23387 | MEDIUM | 6.1 | 1.1% | May 24, 2021 | The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the UR... |
| CVE-2021-30083 | MEDIUM | 6.1 | 0.8% | May 24, 2021 | An issue was discovered in Mediat 1.4.1. There is a Reflected XSS vulnerability which allows remote attackers to inject ... |
| CVE-2021-30082 | MEDIUM | 6.1 | 0.8% | May 24, 2021 | An issue was discovered in Gris CMS v0.1. There is a Persistent XSS vulnerability which allows remote attackers to injec... |
| CVE-2021-30081 | HIGH | 8.8 | 1.0% | May 24, 2021 | An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement ... |
| CVE-2021-29256 | HIGH | 8.8 | 3.0% | May 24, 2021 | . The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information d... |
| CVE-2021-32624 | MEDIUM | 5.3 | 0.9% | May 24, 2021 | Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly disco... |
| CVE-2021-33502 | HIGH | 7.5 | 1.7% | May 24, 2021 | The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expressi... |
| CVE-2021-32629 | HIGH | 8.8 | 0.5% | May 24, 2021 | Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermedi... |
| CVE-2021-29300 | CRITICAL | 9.8 | 4.5% | May 24, 2021 | The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote a... |
| CVE-2021-33516 | HIGH | 8.1 | 1.1% | May 24, 2021 | An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web se... |
| CVE-2021-3485 | MEDIUM | 6.6 | 0.9% | May 24, 2021 | An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linu... |
| CVE-2021-20557 | HIGH | 7.2 | 2.7% | May 24, 2021 | IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by se... |
| CVE-2021-20428 | MEDIUM | 5.3 | 1.3% | May 24, 2021 | IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error... |
| CVE-2021-20426 | CRITICAL | 9.8 | 1.0% | May 24, 2021 | IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i... |
| CVE-2021-20419 | HIGH | 7.5 | 0.7% | May 24, 2021 | IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi... |
| CVE-2021-20389 | HIGH | 7.8 | 0.2% | May 24, 2021 | IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID... |
| CVE-2021-20386 | MEDIUM | 6.1 | 0.7% | May 24, 2021 | IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2021-20385 | HIGH | 7.2 | 2.1% | May 24, 2021 | IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By s... |
| CVE-2021-32075 | CRITICAL | 9.8 | 1.8% | May 24, 2021 | Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization. |
| CVE-2021-3559 | MEDIUM | 6.5 | 1.0% | May 24, 2021 | A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with... |
| CVE-2021-21989 | MEDIUM | 6.5 | 0.5% | May 24, 2021 | VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read... |
| CVE-2021-21988 | MEDIUM | 6.5 | 0.5% | May 24, 2021 | VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read... |
| CVE-2021-21987 | MEDIUM | 6.5 | 0.6% | May 24, 2021 | VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now