2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0873HIGH7.8In PVRSRVBridgeRGXKickRS of the PowerVR kernel driver, a missing size check means there is a possible integer overflow t...
CVE-2021-0872HIGH7.8In PVRSRVBridgeRGXKickVRDM of the PowerVR kernel driver, a missing size check means there is a possible integer overflow...
CVE-2021-43819MEDIUM5.3Stargate-Bukkit is a mod for the minecraft video game which adds a portal focused environment. In affected versions Mine...
CVE-2021-28254CRITICAL9.8A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary comma...
CVE-2021-41614HIGH7.8An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to th...
CVE-2021-41613MEDIUM4.3An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The write logic of Exception Effective ...
CVE-2021-41612HIGH8.8An issue was discovered in the ALU unit of the OpenRISC mor1kx processor. The carry flag is not being updated correctly ...
CVE-2021-40507CRITICAL9.8An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o...
CVE-2021-40506CRITICAL9.8An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o...
CVE-2021-33797CRITICAL9.8Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() rea...
CVE-2021-36520HIGH7.5A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI.
CVE-2021-33990CRITICAL9.8Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The...
CVE-2021-45464HIGH8.8kvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest...
CVE-2021-43612HIGH7.5In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bou...
CVE-2021-39295HIGH7.5In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI l...
CVE-2021-34337MEDIUM6.3An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks t...
CVE-2021-30153MEDIUM4.3An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35...
CVE-2021-46880CRITICAL9.8x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an ...
CVE-2021-46879HIGH7.8An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in...
CVE-2021-46878HIGH7.8An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to...
CVE-2021-45985HIGH7.5In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read.
CVE-2021-3267HIGH7.2File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile f...
CVE-2021-31707CRITICAL9.8Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type.
CVE-2021-28235CRITICAL9.8Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug func...
CVE-2021-41526HIGH7.8A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerabil...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now