2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-33525HIGH8.8EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in...
CVE-2021-30108CRITICAL9.1Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Refer...
CVE-2021-23387MEDIUM6.1The package trailing-slash before 2.0.1 are vulnerable to Open Redirect via the use of trailing double slashes in the UR...
CVE-2021-30083MEDIUM6.1An issue was discovered in Mediat 1.4.1. There is a Reflected XSS vulnerability which allows remote attackers to inject ...
CVE-2021-30082MEDIUM6.1An issue was discovered in Gris CMS v0.1. There is a Persistent XSS vulnerability which allows remote attackers to injec...
CVE-2021-30081HIGH8.8An issue was discovered in emlog 6.0.0stable. There is a SQL Injection vulnerability that can execute any SQL statement ...
CVE-2021-29256HIGH8.8. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information d...
CVE-2021-32624MEDIUM5.3Keystone 5 is an open source CMS platform to build Node.js applications. This security advisory relates to a newly disco...
CVE-2021-33502HIGH7.5The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expressi...
CVE-2021-32629HIGH8.8Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermedi...
CVE-2021-29300CRITICAL9.8The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote a...
CVE-2021-33516HIGH8.1An issue was discovered in GUPnP before 1.0.7 and 1.1.x and 1.2.x before 1.2.5. It allows DNS rebinding. A remote web se...
CVE-2021-3485MEDIUM6.6An Improper Input Validation vulnerability in the Product Update feature of Bitdefender Endpoint Security Tools for Linu...
CVE-2021-20557HIGH7.2IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by se...
CVE-2021-20428MEDIUM5.3IBM Security Guardium 11.2 could allow a remote attacker to obtain sensitive information when a detailed technical error...
CVE-2021-20426CRITICAL9.8IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i...
CVE-2021-20419HIGH7.5IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi...
CVE-2021-20389HIGH7.8IBM Security Guardium 11.2 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID...
CVE-2021-20386MEDIUM6.1IBM Security Guardium 11.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2021-20385HIGH7.2IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By s...
CVE-2021-32075CRITICAL9.8Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
CVE-2021-3559MEDIUM6.5A flaw was found in libvirt in the virConnectListAllNodeDevices API in versions before 7.0.0. It only affects hosts with...
CVE-2021-21989MEDIUM6.5VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read...
CVE-2021-21988MEDIUM6.5VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read...
CVE-2021-21987MEDIUM6.5VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now