2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38513 | CRITICAL | 9.8 | 1.8% | Aug 11, 2021 | Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.10.11, RBR850 before 3.2.1... |
| CVE-2021-20032 | CRITICAL | 9.8 | 2.0% | Aug 10, 2021 | SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vul... |
| CVE-2021-37425 | CRITICAL | 9.1 | 66.3% | Aug 10, 2021 | Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workfl... |
| CVE-2021-38384 | CRITICAL | 9.8 | 1.5% | Aug 10, 2021 | Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a... |
| CVE-2021-38383 | CRITICAL | 9.8 | 1.2% | Aug 10, 2021 | OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c. |
| CVE-2021-38140 | CRITICAL | 9.8 | 1.3% | Aug 10, 2021 | The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AU... |
| CVE-2021-32943 | CRITICAL | 9.8 | 1.9% | Aug 10, 2021 | The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arb... |
| CVE-2021-32798 | CRITICAL | 9.6 | 2.1% | Aug 9, 2021 | The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted noteb... |
| CVE-2021-32797 | CRITICAL | 9.6 | 2.6% | Aug 9, 2021 | JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affect... |
| CVE-2021-21564 | CRITICAL | 9.8 | 1.6% | Aug 9, 2021 | Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenti... |
| CVE-2021-22910 | CRITICAL | 9.8 | 2.3% | Aug 9, 2021 | A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an ... |
| CVE-2021-24507 | CRITICAL | 9.8 | 11.3% | Aug 9, 2021 | The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from t... |
| CVE-2021-24499 | CRITICAL | 9.8 | 60.4% | Aug 9, 2021 | The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader... |
| CVE-2021-38197 | CRITICAL | 9.8 | 2.1% | Aug 8, 2021 | unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR arc... |
| CVE-2021-23419 | CRITICAL | 9.8 | 1.1% | Aug 8, 2021 | This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying propertie... |
| CVE-2021-38196 | CRITICAL | 9.8 | 2.6% | Aug 8, 2021 | An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote... |
| CVE-2021-38195 | CRITICAL | 9.8 | 0.9% | Aug 8, 2021 | An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it a... |
| CVE-2021-38194 | CRITICAL | 9.8 | 1.3% | Aug 8, 2021 | An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the Fiel... |
| CVE-2021-38190 | CRITICAL | 9.8 | 1.4% | Aug 8, 2021 | An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it d... |
| CVE-2021-38189 | CRITICAL | 9.8 | 1.5% | Aug 8, 2021 | An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . ... |
| CVE-2021-38188 | CRITICAL | 9.8 | 1.3% | Aug 8, 2021 | An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. In Decoder::new(), slice.get_unchecked(slice.leng... |
| CVE-2021-38187 | CRITICAL | 9.8 | 1.4% | Aug 8, 2021 | An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a ... |
| CVE-2021-38173 | CRITICAL | 9.8 | 3.2% | Aug 7, 2021 | Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh... |
| CVE-2021-38167 | CRITICAL | 9.8 | 1.3% | Aug 7, 2021 | Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to by... |
| CVE-2021-38159 | CRITICAL | 9.8 | 1.9% | Aug 7, 2021 | In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web appl... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now