2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26569HIGH8.1Race Condition within a Thread vulnerability in iscsi_snapshot_comm_core in Synology DiskStation Manager (DSM) before 6....
CVE-2021-20674HIGH7.8Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows a...
CVE-2021-28154CRITICAL9.1Camunda Modeler (aka camunda-modeler) through 4.6.0 allows arbitrary file access. A remote attacker may send a crafted I...
CVE-2021-28153MEDIUM5.3An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATIO...
CVE-2021-28143HIGH8/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (...
CVE-2021-22714CRITICAL9.8A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION...
CVE-2021-22713HIGH7.5A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION...
CVE-2021-22712HIGH7.8A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Gr...
CVE-2021-22711HIGH7.8A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Gr...
CVE-2021-22710HIGH7.8A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Gr...
CVE-2021-22709HIGH7.8A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Gr...
CVE-2021-20261MEDIUM6.4A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The ...
CVE-2021-28144HIGH8.8prog.cgi on D-Link DIR-3060 devices before 1.11b04 HF2 allows remote authenticated users to inject arbitrary commands in...
CVE-2021-28141CRITICAL9.8An issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAj...
CVE-2021-28088MEDIUM5.4Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to i...
CVE-2021-27679MEDIUM5.4Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary ...
CVE-2021-27678MEDIUM5.4Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary we...
CVE-2021-27677MEDIUM5.4Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary w...
CVE-2021-26776MEDIUM5.4CSZ CMS 1.2.9 is affected by a cross-site scripting (XSS) vulnerability in multiple pages through the field name.
CVE-2021-21381HIGH8.2Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since v...
CVE-2021-27085HIGH8.8Internet Explorer Remote Code Execution Vulnerability
CVE-2021-27084HIGH7.8Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
CVE-2021-27083HIGH7.8Remote Development Extension for Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-27082HIGH7.8Quantum Development Kit for Visual Studio Code Remote Code Execution Vulnerability
CVE-2021-27081HIGH7.8Visual Studio Code ESLint Extension Remote Code Execution Vulnerability

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now