2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25372MEDIUM6.7An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
CVE-2021-25371MEDIUM6.7A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
CVE-2021-25370MEDIUM4.4An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory cor...
CVE-2021-25369MEDIUM5.5An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel inform...
CVE-2021-22886MEDIUM6.1Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdo...
CVE-2021-29255HIGH7.5MicroSeven MYM71080i-B 2.0.5 through 2.0.20 devices send admin credentials in cleartext to pnp.microseven.com TCP port 7...
CVE-2021-21403CRITICAL9.8In github.com/kongchuanhujiao/server before version 1.3.21 there is an authentication Bypass by Primary Weakness vulnera...
CVE-2021-20289MEDIUM5.3A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are retu...
CVE-2021-20285MEDIUM6.6A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SE...
CVE-2021-20284MEDIUM5.5A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_s...
CVE-2021-20271HIGH7A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who ca...
CVE-2021-20197MEDIUM6.3There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar,...
CVE-2021-20193LOW3.3A flaw was found in the src/list.c of tar 1.33 and earlier. This flaw allows an attacker who can submit a crafted input ...
CVE-2021-1629MEDIUM6.1Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
CVE-2021-1628CRITICAL9.8MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component th...
CVE-2021-1627CRITICAL9.8MuleSoft is aware of a Server Side Request Forgery vulnerability affecting certain versions of a Mule runtime component ...
CVE-2021-1626CRITICAL9.8MuleSoft is aware of a Remote Code Execution vulnerability affecting certain versions of a Mule runtime component that m...
CVE-2021-3109MEDIUM4.8The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context ...
CVE-2021-22506HIGH7.5Advance configuration exposing Information Leakage vulnerability in Micro Focus Access Manager product, affects all vers...
CVE-2021-3275MEDIUM6.1Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless A...
CVE-2021-23890MEDIUM6.5Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ...
CVE-2021-23889MEDIUM4.8Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrator...
CVE-2021-23888MEDIUM6.3Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could ca...
CVE-2021-20683MEDIUM5.4Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 all...
CVE-2021-20682HIGH7.2baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS comma...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now