2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21552HIGH8.8Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. ...
CVE-2021-21549HIGH8.8Dell EMC XtremIO Versions prior to 6.3.3-8, contain a Cross-Site Request Forgery Vulnerability in XMS. A non-privileged ...
CVE-2021-32634HIGH7.2Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserial...
CVE-2021-29681MEDIUM5.3IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters i...
CVE-2021-27811HIGH7.2A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execu...
CVE-2021-31475HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Orion Job S...
CVE-2021-31474CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Per...
CVE-2021-31473HIGH7.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Reader 10.1.3.37...
CVE-2021-31440HIGH7This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel 5.11.15. An a...
CVE-2021-31439HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Synology Dis...
CVE-2021-32633HIGH8.8Zope is an open-source web application server. In Zope versions prior to 4.6 and 5.2, users can access untrusted modules...
CVE-2021-29415MEDIUM5.5The elliptic curve cryptography (ECC) hardware accelerator, part of the ARM® TrustZone® CryptoCell 310, contained in the...
CVE-2021-29414MEDIUM6.1STMicroelectronics STM32L4 devices through 2021-03-29 have incorrect physical access control.
CVE-2021-32032HIGH7.5In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the e...
CVE-2021-28798HIGH7.5A relative path traversal vulnerability has been reported to affect QNAP NAS running QTS and QuTS hero. If exploited, th...
CVE-2021-33477HIGH8.8rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improp...
CVE-2021-22409MEDIUM5.3There is a denial of service vulnerability in some versions of ManageOne. There is a logic error in the implementation o...
CVE-2021-22339MEDIUM6.5There is a denial of service vulnerability in some versions of ManageOne. In specific scenarios, due to the insufficient...
CVE-2021-28906HIGH7.5In function read_yin_leaf() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. In som...
CVE-2021-28905HIGH7.5In function lys_node_free() in libyang <= v1.0.225, it asserts that the value of node->module can't be NULL. But in some...
CVE-2021-28904HIGH7.5In function ext_get_plugin() in libyang <= v1.0.225, it doesn't check whether the value of revision is NULL. If revision...
CVE-2021-28903HIGH7.5A stack overflow in libyang <= v1.0.225 can cause a denial of service through function lyxml_parse_mem(). lyxml_parse_el...
CVE-2021-28902HIGH7.5In function read_yin_container() in libyang <= v1.0.225, it doesn't check whether the value of retval->ext[r] is NULL. I...
CVE-2021-27956MEDIUM6.1Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user s...
CVE-2021-32630HIGH8.8Admidio is a free, open source user management system for websites of organizations and groups. In Admidio before versio...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now