2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23351 | MEDIUM | 4.9 | 1.9% | Mar 8, 2021 | The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1(... |
| CVE-2021-27365 | HIGH | 7.8 | 2.1% | Mar 7, 2021 | An issue was discovered in the Linux kernel through 5.11.3. Certain iSCSI data structures do not have appropriate length... |
| CVE-2021-27364 | HIGH | 7.1 | 1.0% | Mar 7, 2021 | An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by... |
| CVE-2021-27363 | MEDIUM | 4.4 | 0.7% | Mar 7, 2021 | An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address o... |
| CVE-2021-26294 | HIGH | 7.5 | 17.3% | Mar 7, 2021 | An issue was discovered in AfterLogic Aurora through 7.7.9 and WebMail Pro through 7.7.9. They allow directory traversal... |
| CVE-2021-26814 | HIGH | 8.8 | 8.7% | Mar 6, 2021 | Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileg... |
| CVE-2021-27581 | CRITICAL | 9.8 | 1.6% | Mar 5, 2021 | The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter. |
| CVE-2021-28042 | HIGH | 7.8 | 3.3% | Mar 5, 2021 | Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload fea... |
| CVE-2021-3420 | CRITICAL | 9.8 | 2.1% | Mar 5, 2021 | A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions m... |
| CVE-2021-3377 | MEDIUM | 6.1 | 8.0% | Mar 5, 2021 | The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTM... |
| CVE-2021-28041 | HIGH | 7.1 | 3.4% | Mar 5, 2021 | ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstra... |
| CVE-2021-27257 | MEDIUM | 6.5 | 0.3% | Mar 5, 2021 | This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i... |
| CVE-2021-27256 | HIGH | 8.8 | 0.9% | Mar 5, 2021 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R780... |
| CVE-2021-27255 | HIGH | 8.8 | 1.3% | Mar 5, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of NETGEAR R7800 firmware... |
| CVE-2021-27254 | HIGH | 8.8 | 0.5% | Mar 5, 2021 | This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R7800... |
| CVE-2021-26705 | CRITICAL | 9.1 | 2.1% | Mar 5, 2021 | An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive RMI methods such as getC... |
| CVE-2021-28040 | HIGH | 7.5 | 1.2% | Mar 5, 2021 | An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in os_xml.c occurs when a large number o... |
| CVE-2021-28039 | MEDIUM | 6.5 | 0.4% | Mar 5, 2021 | An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, ... |
| CVE-2021-28038 | MEDIUM | 6.5 | 0.7% | Mar 5, 2021 | An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver la... |
| CVE-2021-27099 | MEDIUM | 6.8 | 0.7% | Mar 5, 2021 | In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the ... |
| CVE-2021-27098 | HIGH | 8.1 | 0.6% | Mar 5, 2021 | In SPIRE 0.8.1 through 0.8.4 and before versions 0.9.4, 0.10.2, 0.11.3 and 0.12.1, specially crafted requests to the Fet... |
| CVE-2021-26971 | MEDIUM | 6.3 | 1.3% | Mar 5, 2021 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver... |
| CVE-2021-26970 | MEDIUM | 6.3 | 1.3% | Mar 5, 2021 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver... |
| CVE-2021-26969 | MEDIUM | 6.5 | 1.4% | Mar 5, 2021 | A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management ... |
| CVE-2021-26968 | MEDIUM | 4.8 | 0.6% | Mar 5, 2021 | A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platfo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now