2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23379 | CRITICAL | 9.8 | 1.3% | Apr 18, 2021 | This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an att... |
| CVE-2021-23378 | CRITICAL | 9.8 | 1.9% | Apr 18, 2021 | This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is poss... |
| CVE-2021-23377 | CRITICAL | 9.8 | 3.0% | Apr 18, 2021 | This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, i... |
| CVE-2021-23376 | CRITICAL | 9.8 | 1.9% | Apr 18, 2021 | This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, ... |
| CVE-2021-23375 | CRITICAL | 9.8 | 1.3% | Apr 18, 2021 | This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is poss... |
| CVE-2021-23374 | CRITICAL | 9.8 | 1.3% | Apr 18, 2021 | This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is ... |
| CVE-2021-3493 | HIGH | 7.8 | 44.0% | Apr 17, 2021 | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o... |
| CVE-2021-3492 | HIGH | 7.8 | 1.5% | Apr 17, 2021 | Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring ... |
| CVE-2021-29452 | MEDIUM | 6.5 | 0.8% | Apr 16, 2021 | a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow ed... |
| CVE-2021-29451 | CRITICAL | 9.1 | 0.9% | Apr 16, 2021 | Portofino is an open source web development framework. Portofino before version 5.2.1 did not properly verify the signat... |
| CVE-2021-29446 | MEDIUM | 5.9 | 1.2% | Apr 16, 2021 | jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 ... |
| CVE-2021-29445 | MEDIUM | 5.9 | 1.2% | Apr 16, 2021 | jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 ... |
| CVE-2021-29444 | MEDIUM | 5.9 | 1.2% | Apr 16, 2021 | jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 t... |
| CVE-2021-27394 | HIGH | 8.8 | 0.8% | Apr 16, 2021 | A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.19), Mendix Applications... |
| CVE-2021-31348 | MEDIUM | 6.5 | 1.1% | Apr 16, 2021 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling ... |
| CVE-2021-31347 | MEDIUM | 6.5 | 1.2% | Apr 16, 2021 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling ... |
| CVE-2021-29443 | MEDIUM | 5.9 | 1.2% | Apr 16, 2021 | jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorith... |
| CVE-2021-26830 | CRITICAL | 9.1 | 4.6% | Apr 16, 2021 | SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin... |
| CVE-2021-20491 | MEDIUM | 4.4 | 0.3% | Apr 16, 2021 | IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking d... |
| CVE-2021-22539 | HIGH | 7.8 | 0.3% | Apr 16, 2021 | An attacker can place a crafted JSON config file into the project folder pointing to a custom executable. VScode-bazel a... |
| CVE-2021-31414 | CRITICAL | 9.8 | 2.4% | Apr 16, 2021 | The unofficial vscode-rpm-spec extension before 0.3.2 for Visual Studio Code allows remote code execution via a crafted ... |
| CVE-2021-26074 | MEDIUM | 6.5 | 0.7% | Apr 16, 2021 | Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect... |
| CVE-2021-26073 | HIGH | 7.7 | 0.9% | Apr 16, 2021 | Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Expr... |
| CVE-2021-27692 | CRITICAL | 9.8 | 3.3% | Apr 16, 2021 | Command Injection in Tenda G1 and G3 routers with firmware versions v15.11.0.17(9502)_CN or v15.11.0.16(9024)_CN allows ... |
| CVE-2021-27691 | CRITICAL | 9.8 | 25.2% | Apr 16, 2021 | Command Injection in Tenda G0 routers with firmware versions v15.11.0.6(9039)_CN and v15.11.0.5(5876)_CN , and Tenda G1 ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now