2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-38513CRITICAL9.8Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.10.11, RBR850 before 3.2.1...
CVE-2021-20032CRITICAL9.8SonicWall Analytics 2.5 On-Prem is vulnerable to Java Debug Wire Protocol (JDWP) interface security misconfiguration vul...
CVE-2021-37425CRITICAL9.1Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workfl...
CVE-2021-38384CRITICAL9.8Serverless Offline 8.0.0 returns a 403 HTTP status code for a route that has a trailing / character, which might cause a...
CVE-2021-38383CRITICAL9.8OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c.
CVE-2021-38140CRITICAL9.8The set_user extension module before 2.0.1 for PostgreSQL allows a potential privilege escalation using RESET SESSION AU...
CVE-2021-32943CRITICAL9.8The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arb...
CVE-2021-32798CRITICAL9.6The Jupyter notebook is a web-based notebook environment for interactive computing. In affected versions untrusted noteb...
CVE-2021-32797CRITICAL9.6JupyterLab is a user interface for Project Jupyter which will eventually replace the classic Jupyter Notebook. In affect...
CVE-2021-21564CRITICAL9.8Dell OpenManage Enterprise versions prior to 3.6.1 contain an improper authentication vulnerability. A remote unauthenti...
CVE-2021-22910CRITICAL9.8A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an ...
CVE-2021-24507CRITICAL9.8The Astra Pro Addon WordPress plugin before 3.5.2 did not properly sanitise or escape some of the POST parameters from t...
CVE-2021-24499CRITICAL9.8The Workreap WordPress theme before 2.2.2 AJAX actions workreap_award_temp_file_uploader and workreap_temp_file_uploader...
CVE-2021-38197CRITICAL9.8unarr.go in go-unarr (aka Go bindings for unarr) 0.1.1 allows Directory Traversal via ../ in a pathname within a TAR arc...
CVE-2021-23419CRITICAL9.8This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying propertie...
CVE-2021-38196CRITICAL9.8An issue was discovered in the better-macro crate through 2021-07-22 for Rust. It intentionally demonstrates that remote...
CVE-2021-38195CRITICAL9.8An issue was discovered in the libsecp256k1 crate before 0.5.0 for Rust. It can verify an invalid signature because it a...
CVE-2021-38194CRITICAL9.8An issue was discovered in the ark-r1cs-std crate before 0.3.1 for Rust. It does not enforce any constraints in the Fiel...
CVE-2021-38190CRITICAL9.8An issue was discovered in the nalgebra crate before 0.27.1 for Rust. It allows out-of-bounds memory access because it d...
CVE-2021-38189CRITICAL9.8An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . ...
CVE-2021-38188CRITICAL9.8An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. In Decoder::new(), slice.get_unchecked(slice.leng...
CVE-2021-38187CRITICAL9.8An issue was discovered in the anymap crate through 0.12.1 for Rust. It violates soundness via conversion of a *u8 to a ...
CVE-2021-38173CRITICAL9.8Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh...
CVE-2021-38167CRITICAL9.8Roxy-WI through 5.2.2.0 allows SQL Injection via check_login. An unauthenticated attacker can extract a valid uuid to by...
CVE-2021-38159CRITICAL9.8In certain Progress MOVEit Transfer versions before 2021.0.4 (aka 13.0.4), SQL injection in the MOVEit Transfer web appl...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now