2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31517HIGH7.5Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an...
CVE-2021-20254MEDIUM6.8A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids...
CVE-2021-29250MEDIUM5.4BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products...
CVE-2021-29248MEDIUM5.3BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set th...
CVE-2021-29247MEDIUM5.3BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set th...
CVE-2021-29246MEDIUM6.7BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achiev...
CVE-2021-29245MEDIUM5.3BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key.
CVE-2021-31800CRITICAL9.8Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a...
CVE-2021-25317LOW3.3A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE...
CVE-2021-25319HIGH7.8A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers ...
CVE-2021-25179MEDIUM6.1SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.
CVE-2021-26804MEDIUM6.5Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validatio...
CVE-2021-29478HIGH8.8Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. A...
CVE-2021-29477HIGH8.8Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. A...
CVE-2021-21551HIGH7.8Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile...
CVE-2021-3154HIGH7.5An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords v...
CVE-2021-22547HIGH7.8In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in m...
CVE-2021-29240HIGH7.8The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before insta...
CVE-2021-23383CRITICAL9.8The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to co...
CVE-2021-23343HIGH7.5All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, spl...
CVE-2021-31164HIGH7.5Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements.
CVE-2021-32020CRITICAL9.8The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memo...
CVE-2021-21264MEDIUM5.2October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 ...
CVE-2021-29242HIGH7.3CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication p...
CVE-2021-29241HIGH7.5CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now