2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-28832HIGH7.8VSCodeVim before 1.19.0 allows attackers to execute arbitrary code via a crafted workspace configuration.
CVE-2021-30127HIGH7.3TerraMaster F2-210 devices through 2021-04-03 use UPnP to make the admin web server accessible over the Internet on TCP ...
CVE-2021-21533MEDIUM4.3Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a den...
CVE-2021-21532MEDIUM6.3Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be p...
CVE-2021-21529MEDIUM5.5Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malic...
CVE-2021-30074MEDIUM6.1docsify 4.12.1 is affected by Cross Site Scripting (XSS) because the search component does not appropriately encode Code...
CVE-2021-30126MEDIUM6.5Lightmeter ControlCenter 1.1.0 through 1.5.x before 1.5.1 allows anyone who knows the URL of a publicly available Lightm...
CVE-2021-30125MEDIUM6.1Jamf Pro before 10.28.0 allows XSS related to inventory history, aka PI-009376.
CVE-2021-30072CRITICAL9.8An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based...
CVE-2021-28941MEDIUM5.3Because of no validation on a curl command in MagpieRSS 0.72 in the /extlib/Snoopy.class.inc file, when you send a reque...
CVE-2021-28940CRITICAL9.8Because of a incorrect escaped exec command in MagpieRSS in 0.72 in the /extlib/Snoopy.class.inc file, it is possible to...
CVE-2021-3374MEDIUM5.3Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involvin...
CVE-2021-29661MEDIUM5.4Softing AG OPC Toolbox through 4.10.1.13035 allows /en/diag_values.html Stored XSS via the ITEMLISTVALUES##ITEMID parame...
CVE-2021-29660HIGH8.8A Cross-Site Request Forgery (CSRF) vulnerability in en/cfg_setpwd.html in Softing AG OPC Toolbox through 4.10.1.13035 a...
CVE-2021-27973HIGH7.2SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
CVE-2021-1879MEDIUM6.1This issue was addressed by improved management of object lifetimes. This issue is fixed in iOS 12.5.2, iOS 14.4.2 and i...
CVE-2021-1871CRITICAL9.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-...
CVE-2021-1870CRITICAL9.8A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-...
CVE-2021-1844HIGH8.8A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 14.4.1 and iPadOS 14.4.1, S...
CVE-2021-1818CRITICAL9.8A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2...
CVE-2021-1806HIGH7A race condition was addressed with additional validation. This issue is fixed in macOS Big Sur 11.2.1, macOS Catalina 1...
CVE-2021-1805HIGH7.8An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2.1, macOS ...
CVE-2021-1803LOW3.3The issue was addressed with improved permissions logic. This issue is fixed in macOS Big Sur 11.0.1. A local applicatio...
CVE-2021-1802HIGH7.8A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2...
CVE-2021-1801MEDIUM6.5This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security U...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now