2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25292MEDIUM6.5An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a craf...
CVE-2021-25291HIGH7.5An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is an out-of-bounds read in TiffreadRGBATile via ...
CVE-2021-25290HIGH7.5An issue was discovered in Pillow before 8.1.1. In TiffDecode.c, there is a negative-offset memcpy with an invalid size.
CVE-2021-25289CRITICAL9.8An issue was discovered in Pillow before 8.1.1. TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr ...
CVE-2021-3327MEDIUM5.4Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter.
CVE-2021-28109MEDIUM6.1TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).
CVE-2021-27928HIGH7.2A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a...
CVE-2021-27221HIGH8.1MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /expo...
CVE-2021-28653MEDIUM6.5The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They ...
CVE-2021-26275CRITICAL9.8The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function...
CVE-2021-21384HIGH7.8shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to d...
CVE-2021-27436MEDIUM6.1WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malici...
CVE-2021-3416MEDIUM6A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and incl...
CVE-2021-27358HIGH7.5The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of...
CVE-2021-25764MEDIUM5.3In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.
CVE-2021-28160MEDIUM6.1Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value w...
CVE-2021-1287HIGH7.2A vulnerability in the web-based management interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDS...
CVE-2021-27656HIGH7.5A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-le...
CVE-2021-22665HIGH7.8Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a loc...
CVE-2021-21383MEDIUM5.4Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scri...
CVE-2021-28796MEDIUM6.1Increments Qiita::Markdown before 0.33.0 allows XSS in transformers.
CVE-2021-28794CRITICAL9.8The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath.
CVE-2021-28792HIGH7.8The unofficial Swift Development Environment extension before 2.12.1 for Visual Studio Code allows remote attackers to e...
CVE-2021-28791HIGH7.8The unofficial SwiftFormat extension before 1.3.7 for Visual Studio Code allows remote attackers to execute arbitrary co...
CVE-2021-28790HIGH7.8The unofficial SwiftLint extension before 1.4.5 for Visual Studio Code allows remote attackers to execute arbitrary code...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now