2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31517 | HIGH | 7.5 | 1.1% | May 5, 2021 | Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an... |
| CVE-2021-20254 | MEDIUM | 6.8 | 1.6% | May 5, 2021 | A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids... |
| CVE-2021-29250 | MEDIUM | 5.4 | 0.5% | May 5, 2021 | BTCPay Server through 1.0.7.0 suffers from a Stored Cross Site Scripting (XSS) vulnerability within the POS Add Products... |
| CVE-2021-29248 | MEDIUM | 5.3 | 0.8% | May 5, 2021 | BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set th... |
| CVE-2021-29247 | MEDIUM | 5.3 | 1.2% | May 5, 2021 | BTCPay Server through 1.0.7.0 could allow a remote attacker to obtain sensitive information, caused by failure to set th... |
| CVE-2021-29246 | MEDIUM | 6.7 | 1.5% | May 5, 2021 | BTCPay Server through 1.0.7.0 suffers from directory traversal, which allows an attacker with admin privileges to achiev... |
| CVE-2021-29245 | MEDIUM | 5.3 | 0.9% | May 5, 2021 | BTCPay Server through 1.0.7.0 uses a weak method Next to produce pseudo-random values to generate a legacy API key. |
| CVE-2021-31800 | CRITICAL | 9.8 | 19.3% | May 5, 2021 | Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a... |
| CVE-2021-25317 | LOW | 3.3 | 0.3% | May 5, 2021 | A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE... |
| CVE-2021-25319 | HIGH | 7.8 | 0.3% | May 5, 2021 | A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers ... |
| CVE-2021-25179 | MEDIUM | 6.1 | 1.4% | May 5, 2021 | SolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header. |
| CVE-2021-26804 | MEDIUM | 6.5 | 1.2% | May 4, 2021 | Insecure Permissions in Centreon Web versions 19.10.18, 20.04.8, and 20.10.2 allows remote attackers to bypass validatio... |
| CVE-2021-29478 | HIGH | 8.8 | 3.7% | May 4, 2021 | Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. A... |
| CVE-2021-29477 | HIGH | 8.8 | 4.2% | May 4, 2021 | Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. A... |
| CVE-2021-21551 | HIGH | 7.8 | 57.5% | May 4, 2021 | Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile... |
| CVE-2021-3154 | HIGH | 7.5 | 1.2% | May 4, 2021 | An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords v... |
| CVE-2021-22547 | HIGH | 7.8 | 0.2% | May 4, 2021 | In IoT Devices SDK, there is an implementation of calloc() that doesn't have a length check. An attacker could pass in m... |
| CVE-2021-29240 | HIGH | 7.8 | 0.9% | May 4, 2021 | The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before insta... |
| CVE-2021-23383 | CRITICAL | 9.8 | 4.5% | May 4, 2021 | The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to co... |
| CVE-2021-23343 | HIGH | 7.5 | 2.2% | May 4, 2021 | All versions of package path-parse are vulnerable to Regular Expression Denial of Service (ReDoS) via splitDeviceRe, spl... |
| CVE-2021-31164 | HIGH | 7.5 | 2.3% | May 4, 2021 | Apache Unomi prior to version 1.5.5 allows CRLF log injection because of the lack of escaping in the log statements. |
| CVE-2021-32020 | CRITICAL | 9.8 | 1.3% | May 3, 2021 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memo... |
| CVE-2021-21264 | MEDIUM | 5.2 | 0.3% | May 3, 2021 | October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. A bypass of CVE-2020-26231 ... |
| CVE-2021-29242 | HIGH | 7.3 | 1.1% | May 3, 2021 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication p... |
| CVE-2021-29241 | HIGH | 7.5 | 1.4% | May 3, 2021 | CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS). |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now