2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29258HIGH7.5An issue was discovered in Envoy 1.14.0. There is a remotely exploitable crash for HTTP2 Metadata, because an empty META...
CVE-2021-28683HIGH7.5An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable NULL pointer dereference and crash in T...
CVE-2021-28682HIGH7.5An issue was discovered in Envoy through 1.71.1. There is a remotely exploitable integer overflow in which a very large ...
CVE-2021-23386MEDIUM6.5This affects the package dns-packet before 5.2.2. It creates buffers with allocUnsafe and does not always fill them befo...
CVE-2021-3313MEDIUM5.4Plone CMS until version 5.2.4 has a stored Cross-Site Scripting (XSS) vulnerability in the user fullname property and th...
CVE-2021-32632MEDIUM4.3Pajbot is a Twitch chat bot. Pajbot versions prior to 1.52 are vulnerable to cross-site request forgery (CSRF). Hosters ...
CVE-2021-27432HIGH7.5OPC Foundation UA .NET Standard versions prior to 1.4.365.48 and OPC UA .NET Legacy are vulnerable to an uncontrolled re...
CVE-2021-29692MEDIUM5.9IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure...
CVE-2021-29691HIGH7.5IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it u...
CVE-2021-29688HIGH7.5IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed techni...
CVE-2021-29687MEDIUM5.3IBM Security Identity Manager 7.0.2 could allow a remote user to enumerate usernames due to a difference of responses fr...
CVE-2021-29686HIGH8.8IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they s...
CVE-2021-29683MEDIUM6.5IBM Security Identity Manager 7.0.2 stores user credentials in plain clear text which can be read by an authenticated us...
CVE-2021-29682MEDIUM5.3IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information when a detailed techni...
CVE-2021-25933MEDIUM4.8In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation...
CVE-2021-25931HIGH8.8In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation...
CVE-2021-25929MEDIUM4.8In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation...
CVE-2021-3438HIGH7.8A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could ...
CVE-2021-28112HIGH8.8Draeger X-Dock Firmware before 03.00.13 has Active Debug Code on a debug port, leading to remote code execution by an au...
CVE-2021-28111HIGH8.8Draeger X-Dock Firmware before 03.00.13 has Hard-Coded Credentials, leading to remote code execution by an authenticated...
CVE-2021-27434HIGH7.5Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, a...
CVE-2021-25930MEDIUM4.3In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation...
CVE-2021-3536MEDIUM4.8A flaw was found in Wildfly in versions before 23.0.2.Final while creating a new role in domain mode via the admin conso...
CVE-2021-3480HIGH7.5A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN...
CVE-2021-3426MEDIUM5.7There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now