2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-0229MEDIUM5.3An uncontrolled resource consumption vulnerability in Message Queue Telemetry Transport (MQTT) server of Juniper Network...
CVE-2021-0228MEDIUM6.5An improper check for unusual or exceptional conditions vulnerability in Juniper Networks MX Series platforms with Trio-...
CVE-2021-0227HIGH7.5An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-...
CVE-2021-0226HIGH7.5On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an established IPv6 BGP sessio...
CVE-2021-0225MEDIUM5.8An Improper Check for Unusual or Exceptional Conditions in Juniper Networks Junos OS Evolved may cause the stateless fir...
CVE-2021-0224MEDIUM6.5A vulnerability in the handling of internal resources necessary to bring up a large number of Layer 2 broadband remote a...
CVE-2021-0216MEDIUM6.5A vulnerability in Juniper Networks Junos OS running on the ACX5448 and ACX710 platforms may cause BFD sessions to flap ...
CVE-2021-0214MEDIUM6.5A vulnerability in the distributed or centralized periodic packet management daemon (PPMD) of Juniper Networks Junos OS ...
CVE-2021-3496HIGH7.8A heap-based buffer overflow was found in jhead in version 3.06 in Get16u() in exif.c when processing a crafted file.
CVE-2021-20590HIGH7.5Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 seri...
CVE-2021-31572CRITICAL9.8The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.
CVE-2021-31571CRITICAL9.8The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.
CVE-2021-30356HIGH8.1A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low ...
CVE-2021-28168MEDIUM5.5Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. Thi...
CVE-2021-27278HIGH8.2This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.1.1-4...
CVE-2021-27277HIGH7.8This vulnerability allows local attackers to escalate privileges on affected installations of SolarWinds Orion Virtual I...
CVE-2021-23133HIGH7A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalatio...
CVE-2021-30476CRITICAL9.8HashiCorp Terraform’s Vault Provider (terraform-provider-vault) did not correctly configure GCE-type bound labels for Va...
CVE-2021-29653HIGH7.5HashiCorp Vault and Vault Enterprise 1.5.1 and newer, under certain circumstances, may exclude revoked but unexpired cer...
CVE-2021-27400HIGH7.5HashiCorp Vault and Vault Enterprise Cassandra integrations (storage backend and database secrets engine plugin) did not...
CVE-2021-22540MEDIUM6.1Bad validation logic in the Dart SDK versions prior to 2.12.3 allow an attacker to use an XSS attack via DOM clobbering....
CVE-2021-27736MEDIUM6.5FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFro...
CVE-2021-3287CRITICAL9.8Zoho ManageEngine OpManager before 12.5.329 allows unauthenticated Remote Code Execution due to a general bypass in the ...
CVE-2021-31555HIGH7.5An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. It did not validate the oarc_version (aka o...
CVE-2021-31554MEDIUM5.4An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now