2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23379CRITICAL9.8This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an att...
CVE-2021-23378CRITICAL9.8This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is poss...
CVE-2021-23377CRITICAL9.8This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, i...
CVE-2021-23376CRITICAL9.8This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, ...
CVE-2021-23375CRITICAL9.8This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is poss...
CVE-2021-23374CRITICAL9.8This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is ...
CVE-2021-3493HIGH7.8The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o...
CVE-2021-3492HIGH7.8Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring ...
CVE-2021-29452MEDIUM6.5a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow ed...
CVE-2021-29451CRITICAL9.1Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signat...
CVE-2021-29446MEDIUM5.9jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 ...
CVE-2021-29445MEDIUM5.9jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 ...
CVE-2021-29444MEDIUM5.9jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 t...
CVE-2021-27394HIGH8.8A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications...
CVE-2021-31348MEDIUM6.5An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling ...
CVE-2021-31347MEDIUM6.5An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling ...
CVE-2021-29443MEDIUM5.9jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorith...
CVE-2021-26830CRITICAL9.1SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin...
CVE-2021-20491MEDIUM4.4IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking d...
CVE-2021-22539HIGH7.8An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel a...
CVE-2021-31414CRITICAL9.8The unofficial vscode-rpm-spec extension before 0.3.2 for Visual Studio Code allows remote code execution via a crafted ...
CVE-2021-26074MEDIUM6.5Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect...
CVE-2021-26073HIGH7.7Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Expr...
CVE-2021-27692CRITICAL9.8Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows ...
CVE-2021-27691CRITICAL9.8Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now