2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29493 | HIGH | 8.8 | 0.9% | May 6, 2021 | Kennnyshiwa-cogs contains cogs for Red Discordbot. An RCE exploit has been found in the Tickets module of kennnyshiwa-co... |
| CVE-2021-28665 | HIGH | 7.5 | 1.0% | May 6, 2021 | Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can... |
| CVE-2021-31828 | HIGH | 7.1 | 0.9% | May 6, 2021 | An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate li... |
| CVE-2021-31918 | HIGH | 7.5 | 1.0% | May 6, 2021 | A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to al... |
| CVE-2021-31916 | MEDIUM | 6.7 | 0.7% | May 6, 2021 | An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver m... |
| CVE-2021-31793 | HIGH | 7.5 | 1.3% | May 6, 2021 | An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to s... |
| CVE-2021-3507 | MEDIUM | 6.1 | 0.5% | May 6, 2021 | A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_t... |
| CVE-2021-32052 | MEDIUM | 6.1 | 3.2% | May 6, 2021 | In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibi... |
| CVE-2021-31829 | MEDIUM | 5.5 | 0.3% | May 6, 2021 | kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure o... |
| CVE-2021-28152 | CRITICAL | 9.8 | 5.2% | May 6, 2021 | Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the ... |
| CVE-2021-28151 | HIGH | 8.8 | 27.9% | May 6, 2021 | Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) f... |
| CVE-2021-28150 | MEDIUM | 5.5 | 2.6% | May 6, 2021 | Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and oth... |
| CVE-2021-28149 | MEDIUM | 6.5 | 13.8% | May 6, 2021 | Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user ... |
| CVE-2021-32030 | CRITICAL | 9.8 | 99.4% | May 6, 2021 | The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 ... |
| CVE-2021-30473 | CRITICAL | 9.8 | 2.1% | May 6, 2021 | aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap. |
| CVE-2021-20204 | CRITICAL | 9.8 | 2.2% | May 6, 2021 | A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously cra... |
| CVE-2021-28128 | HIGH | 8.1 | 1.3% | May 6, 2021 | In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password... |
| CVE-2021-22210 | MEDIUM | 5.3 | 1.1% | May 6, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository bra... |
| CVE-2021-22209 | HIGH | 7.5 | 0.9% | May 6, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validati... |
| CVE-2021-22208 | MEDIUM | 4.3 | 0.8% | May 6, 2021 | An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check cou... |
| CVE-2021-22206 | MEDIUM | 4.9 | 1.0% | May 6, 2021 | An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed th... |
| CVE-2021-3501 | HIGH | 7.1 | 0.4% | May 6, 2021 | A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to ... |
| CVE-2021-32062 | MEDIUM | 5.3 | 1.5% | May 6, 2021 | MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 doe... |
| CVE-2021-31616 | HIGH | 8.8 | 2.5% | May 6, 2021 | Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow... |
| CVE-2021-31532 | MEDIUM | 6.8 | 0.5% | May 6, 2021 | NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now