2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25292 | MEDIUM | 6.5 | 1.6% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a craf... |
| CVE-2021-25291 | HIGH | 7.5 | 1.4% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via ... |
| CVE-2021-25290 | HIGH | 7.5 | 2.4% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size. |
| CVE-2021-25289 | CRITICAL | 9.8 | 2.3% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr ... |
| CVE-2021-3327 | MEDIUM | 5.4 | 0.7% | Mar 19, 2021 | Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter. |
| CVE-2021-28109 | MEDIUM | 6.1 | 0.7% | Mar 19, 2021 | TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS). |
| CVE-2021-27928 | HIGH | 7.2 | 38.4% | Mar 19, 2021 | A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a... |
| CVE-2021-27221 | HIGH | 8.1 | 4.5% | Mar 19, 2021 | MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /expo... |
| CVE-2021-28653 | MEDIUM | 6.5 | 0.9% | Mar 19, 2021 | The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They ... |
| CVE-2021-26275 | CRITICAL | 9.8 | 3.0% | Mar 19, 2021 | The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function... |
| CVE-2021-21384 | HIGH | 7.8 | 0.6% | Mar 19, 2021 | shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to d... |
| CVE-2021-27436 | MEDIUM | 6.1 | 0.7% | Mar 18, 2021 | WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malici... |
| CVE-2021-3416 | MEDIUM | 6 | 0.5% | Mar 18, 2021 | A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and incl... |
| CVE-2021-27358 | HIGH | 7.5 | 83.0% | Mar 18, 2021 | The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of... |
| CVE-2021-25764 | MEDIUM | 5.3 | 0.8% | Mar 18, 2021 | In JetBrains PhpStorm before 2020.3, source code could be added to debug logs. |
| CVE-2021-28160 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value w... |
| CVE-2021-1287 | HIGH | 7.2 | 2.2% | Mar 18, 2021 | A vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDS... |
| CVE-2021-27656 | HIGH | 7.5 | 1.2% | Mar 18, 2021 | A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-le... |
| CVE-2021-22665 | HIGH | 7.8 | 0.4% | Mar 18, 2021 | Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a loc... |
| CVE-2021-21383 | MEDIUM | 5.4 | 0.9% | Mar 18, 2021 | Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scri... |
| CVE-2021-28796 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Increments Qiita::Markdown before 0.33.0 allows XSS in transformers. |
| CVE-2021-28794 | CRITICAL | 9.8 | 2.1% | Mar 18, 2021 | The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath. |
| CVE-2021-28792 | HIGH | 7.8 | 1.7% | Mar 18, 2021 | The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to e... |
| CVE-2021-28791 | HIGH | 7.8 | 1.6% | Mar 18, 2021 | The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary co... |
| CVE-2021-28790 | HIGH | 7.8 | 1.7% | Mar 18, 2021 | The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now