2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20334HIGH7.8A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary ...
CVE-2021-30146MEDIUM5.4Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."
CVE-2021-30140MEDIUM5.4LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrat...
CVE-2021-29424HIGH7.5The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of...
CVE-2021-29136MEDIUM5.5Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that...
CVE-2021-26833MEDIUM5.9Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attac...
CVE-2021-30130HIGH7.5phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.
CVE-2021-28658MEDIUM5.3In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via up...
CVE-2021-28142HIGH8.8CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
CVE-2021-30046MEDIUM6.5VIGRA Computer Vision Library Version-1-11-1 contains a segmentation fault vulnerability in the impex.hxx read_image_ban...
CVE-2021-30045CRITICAL9.1SerenityOS 2021-03-27 contains a buffer overflow vulnerability in the EndOfCentralDirectory::read() function.
CVE-2021-28874HIGH7.8SerenityOS fixed as of c9f25bca048443e317f1994ba9b106f2386688c3 contains a buffer overflow vulnerability in LibTextCode ...
CVE-2021-28075HIGH7.5iKuaiOS 3.4.8 Build 202012291059 has an arbitrary file download vulnerability, which can be exploited by attackers to ob...
CVE-2021-27698CRITICAL9.8RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c throug...
CVE-2021-27697CRITICAL9.8RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the g...
CVE-2021-27357CRITICAL9.8RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c.
CVE-2021-27343HIGH7.5SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent)....
CVE-2021-28173CRITICAL9.8The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers c...
CVE-2021-28172HIGH7.5There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers ...
CVE-2021-28171CRITICAL9.8The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions...
CVE-2021-30164CRITICAL9.8Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by lev...
CVE-2021-30163HIGH7.5Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal ...
CVE-2021-30162HIGH7.1An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS servic...
CVE-2021-30161MEDIUM5.5An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection...
CVE-2021-30158MEDIUM5.3An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now