2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-30184HIGH7.8GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is relate...
CVE-2021-30177CRITICAL9.8There is a SQL Injection vulnerability in PHP-Nuke 8.3.3 in the User Registration section, leading to remote code execut...
CVE-2021-26709CRITICAL9.8D-Link DSL-320B-D1 devices through EU_1.25 are prone to multiple Stack-Based Buffer Overflows that allow unauthenticated...
CVE-2021-20692HIGH7.1Directory traversal vulnerability in Archive collectively operation utility Ver.2.10.1.0 and earlier allows an attacker ...
CVE-2021-20691MEDIUM6.1Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unsp...
CVE-2021-20690MEDIUM6.1Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unsp...
CVE-2021-20689MEDIUM6.1Cross-site scripting vulnerability in Yomi-Search Ver4.22 allows remote attackers to inject an arbitrary script via unsp...
CVE-2021-20688MEDIUM6.1Cross-site scripting vulnerability in Click Ranker Ver.3.5 allows remote attackers to inject an arbitrary script via uns...
CVE-2021-20687HIGH8.8Cross-site request forgery (CSRF) vulnerability in Kagemai 0.8.8 allows remote attackers to hijack the authentication of...
CVE-2021-20686MEDIUM6.1Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecifie...
CVE-2021-20685MEDIUM6.1Cross-site scripting vulnerability in Kagemai 0.8.8 allows remote attackers to inject an arbitrary script via unspecifie...
CVE-2021-20684MEDIUM6.1Cross-site scripting vulnerability in MagazinegerZ v.1.01 allows remote attackers to inject an arbitrary script via unsp...
CVE-2021-1892HIGH7.8Memory corruption due to improper input validation while processing IO control which is nonstandard in Snapdragon Comput...
CVE-2021-30147HIGH8.8DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
CVE-2021-30178MEDIUM5.5An issue was discovered in the Linux kernel through 5.11.11. synic_get in arch/x86/kvm/hyperv.c has a NULL pointer deref...
CVE-2021-27900HIGH8.1The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several...
CVE-2021-27899HIGH7.4The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validati...
CVE-2021-22158HIGH7.2The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) i...
CVE-2021-22157MEDIUM6.1Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS.
CVE-2021-25692MEDIUM4.6Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway pri...
CVE-2021-21404HIGH7.5Syncthing is a continuous file synchronization program. In Syncthing before version 1.15.0, the relay server `strelaysrv...
CVE-2021-28688MEDIUM6.5The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or ...
CVE-2021-21423HIGH8.1`projen` is a project generation tool that synthesizes project configuration files such as `package.json`, `tsconfig.jso...
CVE-2021-24027HIGH7.5A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may ha...
CVE-2021-24026CRITICAL9.8A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, W...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now