2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0873 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In PVRSRVBridgeRGXKickRS of the PowerVR kernel driver, a missing size check means there is a possible integer overflow t... |
| CVE-2021-0872 | HIGH | 7.8 | 0.1% | Apr 19, 2023 | In PVRSRVBridgeRGXKickVRDM of the PowerVR kernel driver, a missing size check means there is a possible integer overflow... |
| CVE-2021-43819 | MEDIUM | 5.3 | 0.5% | Apr 19, 2023 | Stargate-Bukkit is a mod for the minecraft video game which adds a portal focused environment. In affected versions Mine... |
| CVE-2021-28254 | CRITICAL | 9.8 | 1.3% | Apr 19, 2023 | A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to execute arbitrary comma... |
| CVE-2021-41614 | HIGH | 7.8 | 0.2% | Apr 18, 2023 | An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The read/write access permissions to th... |
| CVE-2021-41613 | MEDIUM | 4.3 | 0.4% | Apr 18, 2023 | An issue was discovered in the controller unit of the OpenRISC mor1kx processor. The write logic of Exception Effective ... |
| CVE-2021-41612 | HIGH | 8.8 | 1.1% | Apr 18, 2023 | An issue was discovered in the ALU unit of the OpenRISC mor1kx processor. The carry flag is not being updated correctly ... |
| CVE-2021-40507 | CRITICAL | 9.8 | 0.7% | Apr 18, 2023 | An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o... |
| CVE-2021-40506 | CRITICAL | 9.8 | 0.7% | Apr 18, 2023 | An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The o... |
| CVE-2021-33797 | CRITICAL | 9.8 | 0.8% | Apr 17, 2023 | Buffer-overflow in jsdtoa.c in Artifex MuJS in versions 1.0.1 to 1.1.1. An integer overflow happens when js_strtod() rea... |
| CVE-2021-36520 | HIGH | 7.5 | 2.7% | Apr 16, 2023 | A SQL injection vulnerability in I-Tech Trainsmart r1044 exists via a evaluation/assign-evaluation?id= URI. |
| CVE-2021-33990 | CRITICAL | 9.8 | 11.9% | Apr 16, 2023 | Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The... |
| CVE-2021-45464 | HIGH | 8.8 | 0.4% | Apr 15, 2023 | kvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest... |
| CVE-2021-43612 | HIGH | 7.5 | 1.1% | Apr 15, 2023 | In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bou... |
| CVE-2021-39295 | HIGH | 7.5 | 1.3% | Apr 15, 2023 | In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI l... |
| CVE-2021-34337 | MEDIUM | 6.3 | 0.3% | Apr 15, 2023 | An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks t... |
| CVE-2021-30153 | MEDIUM | 4.3 | 0.8% | Apr 15, 2023 | An issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35... |
| CVE-2021-46880 | CRITICAL | 9.8 | 0.6% | Apr 15, 2023 | x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an ... |
| CVE-2021-46879 | HIGH | 7.8 | 0.4% | Apr 11, 2023 | An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in... |
| CVE-2021-46878 | HIGH | 7.8 | 0.4% | Apr 11, 2023 | An issue was discovered in Treasure Data Fluent Bit 1.7.1, erroneous parsing in flb_pack_msgpack_to_json_format leads to... |
| CVE-2021-45985 | HIGH | 7.5 | 1.4% | Apr 10, 2023 | In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read. |
| CVE-2021-3267 | HIGH | 7.2 | 1.3% | Apr 4, 2023 | File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile f... |
| CVE-2021-31707 | CRITICAL | 9.8 | 1.3% | Apr 4, 2023 | Permissions vulnerability found in KiteCMS allows a remote attacker to execute arbitrary code via the upload file type. |
| CVE-2021-28235 | CRITICAL | 9.8 | 1.6% | Apr 4, 2023 | Authentication vulnerability found in Etcd-io v.3.4.10 allows remote attackers to escalate privileges via the debug func... |
| CVE-2021-41526 | HIGH | 7.8 | 0.3% | Mar 29, 2023 | A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerabil... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now