2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20221MEDIUM6An out-of-bounds heap buffer access issue was found in the ARM Generic Interrupt Controller emulator of QEMU up to and i...
CVE-2021-20181HIGH7.5A race condition flaw was found in the 9pfs server implementation of QEMU up to and including 5.2.0. This flaw allows a ...
CVE-2021-3528HIGH8.8A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator ...
CVE-2021-20025HIGH7.8SonicWall Email Security Virtual Appliance version 10.0.9 and earlier versions contain a default username and a password...
CVE-2021-25693HIGH7.5An attacker may cause a Denial of Service (DoS) in multiple versions of Teradici PCoIP Agent via a null pointer derefere...
CVE-2021-20999CRITICAL9.8In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only for device-internal usag...
CVE-2021-20998CRITICAL9.8In multiple managed switches by WAGO in different versions without authorization and with specially crafted packets it i...
CVE-2021-20997HIGH7.5In multiple managed switches by WAGO in different versions it is possible to read out the password hashes of all Web-bas...
CVE-2021-20996MEDIUM5.3In multiple managed switches by WAGO in different versions special crafted requests can lead to cookies being transferre...
CVE-2021-20995HIGH7.5In multiple managed switches by WAGO in different versions the webserver cookies of the web based UI contain user creden...
CVE-2021-20994MEDIUM6.1In multiple managed switches by WAGO in different versions an attacker may trick a legitimate user to click a link to in...
CVE-2021-20993MEDIUM5.3In multiple managed switches by WAGO in different versions the activated directory listing provides an attacker with the...
CVE-2021-20988HIGH7.5In Hilscher rcX RTOS versions prios to V2.1.14.1 the actual UDP packet length is not verified against the length indicat...
CVE-2021-20250MEDIUM4.3A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to informati...
CVE-2021-25694HIGH7.8Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll. An attacker could replace the .dll...
CVE-2021-26311HIGH7.2In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestati...
CVE-2021-22154MEDIUM5.3An Information Disclosure vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and...
CVE-2021-22153HIGH7.3A Remote Code Execution vulnerability in the Management Console component of BlackBerry UEM version(s) 12.13.1 QF2 and e...
CVE-2021-22152MEDIUM5.5A Denial of Service due to Improper Input Validation vulnerability in the Management Console component of BlackBerry UEM...
CVE-2021-20331MEDIUM4.9Specific versions of the MongoDB C# Driver may erroneously publish events containing authentication-related data to a co...
CVE-2021-31215HIGH8.8SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser becaus...
CVE-2021-28799CRITICAL9.8An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exp...
CVE-2021-22155HIGH8.8An Authentication Bypass vulnerability in the SAML Authentication component of BlackBerry Workspaces Server (deployed wi...
CVE-2021-23135MEDIUM5.5Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause le...
CVE-2021-23134HIGH7.8Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their pr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now