2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29493HIGH8.8Kennnyshiwa-cogs contains cogs for Red Discordbot. An RCE exploit has been found in the Tickets module of kennnyshiwa-co...
CVE-2021-28665HIGH7.5Stormshield SNS with versions before 3.7.18, 3.11.6 and 4.1.6 has a memory-management defect in the SNMP plugin that can...
CVE-2021-31828HIGH7.1An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate li...
CVE-2021-31918HIGH7.5A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to al...
CVE-2021-31916MEDIUM6.7An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver m...
CVE-2021-31793HIGH7.5An issue exists on NightOwl WDB-20-V2 WDB-20-V2_20190314 devices that allows an unauthenticated user to gain access to s...
CVE-2021-3507MEDIUM6.1A heap buffer overflow was found in the floppy disk emulator of QEMU up to 6.0.0 (including). It could occur in fdctrl_t...
CVE-2021-32052MEDIUM6.1In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibi...
CVE-2021-31829MEDIUM5.5kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure o...
CVE-2021-28152CRITICAL9.8Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the ...
CVE-2021-28151HIGH8.8Hongdian H8922 3.0.5 devices allow OS command injection via shell metacharacters into the ip-address (aka Destination) f...
CVE-2021-28150MEDIUM5.5Hongdian H8922 3.0.5 devices allow the unprivileged guest user to read cli.conf (with the administrator password and oth...
CVE-2021-28149MEDIUM6.5Hongdian H8922 3.0.5 devices allow Directory Traversal. The /log_download.cgi log export handler does not validate user ...
CVE-2021-32030CRITICAL9.8The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 ...
CVE-2021-30473CRITICAL9.8aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
CVE-2021-20204CRITICAL9.8A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously cra...
CVE-2021-28128HIGH8.1In Strapi through 3.6.0, the admin panel allows the changing of one's own password without entering the current password...
CVE-2021-22210MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2. When querying the repository bra...
CVE-2021-22209HIGH7.5An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.8. GitLab was not properly validati...
CVE-2021-22208MEDIUM4.3An issue has been discovered in GitLab affecting versions starting with 13.5 up to 13.9.7. Improper permission check cou...
CVE-2021-22206MEDIUM4.9An issue has been discovered in GitLab affecting all versions starting from 11.6. Pull mirror credentials are exposed th...
CVE-2021-3501HIGH7.1A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to ...
CVE-2021-32062MEDIUM5.3MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 doe...
CVE-2021-31616HIGH8.8Insufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.1.0 allow a stack buffer overflow...
CVE-2021-31532MEDIUM6.8NXP LPC55S6x microcontrollers (0A and 1B), i.MX RT500 (silicon rev B1 and B2), i.MX RT600 (silicon rev A0, B0), LPC55S6x...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now