2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23351MEDIUM4.9The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1(...
CVE-2021-27365HIGH7.8An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length...
CVE-2021-27364HIGH7.1An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by...
CVE-2021-27363MEDIUM4.4An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address o...
CVE-2021-26294HIGH7.5An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal...
CVE-2021-26814HIGH8.8Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileg...
CVE-2021-27581CRITICAL9.8The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
CVE-2021-28042HIGH7.8Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload fea...
CVE-2021-3420CRITICAL9.8A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions m...
CVE-2021-3377MEDIUM6.1The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTM...
CVE-2021-28041HIGH7.1ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstra...
CVE-2021-27257MEDIUM6.5This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i...
CVE-2021-27256HIGH8.8This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R780...
CVE-2021-27255HIGH8.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware...
CVE-2021-27254HIGH8.8This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800...
CVE-2021-26705CRITICAL9.1An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getC...
CVE-2021-28040HIGH7.5An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number o...
CVE-2021-28039MEDIUM6.5An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, ...
CVE-2021-28038MEDIUM6.5An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver la...
CVE-2021-27099MEDIUM6.8In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the ...
CVE-2021-27098HIGH8.1In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the Fet...
CVE-2021-26971MEDIUM6.3A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver...
CVE-2021-26970MEDIUM6.3A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver...
CVE-2021-26969MEDIUM6.5A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management ...
CVE-2021-26968MEDIUM4.8A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platfo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now