2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-3604CRITICAL9.8Secure 8 (Evalos) does not validate user input data correctly, allowing a remote attacker to perform a Blind SQL Injecti...
CVE-2021-33576CRITICAL9.8An issue was discovered in Cleo LexiCom 5.5.0.0. Within the AS2 message, the sender can specify a filename. This filenam...
CVE-2021-21669CRITICAL9.8Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity...
CVE-2021-23396CRITICAL9.8All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.
CVE-2021-21777CRITICAL10An information disclosure vulnerability exists in the Ethernet/IP UDP handler functionality of EIP Stack Group OpENer 2....
CVE-2021-32691CRITICAL9.8Apollos Apps is an open source platform for launching church-related apps. In Apollos Apps versions prior to 2.20.0, new...
CVE-2021-34813CRITICAL9.8Matrix libolm before 3.2.3 allows a malicious Matrix homeserver to crash a client (while it is attempting to retrieve an...
CVE-2021-27610CRITICAL9.8SAP NetWeaver ABAP Server and ABAP Platform, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 804, does...
CVE-2021-32928CRITICAL9.8The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Ma...
CVE-2021-20093CRITICAL9.1A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker c...
CVE-2021-32685CRITICAL9.8tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signature...
CVE-2021-24037CRITICAL9.8A use after free in hermes, while emitting certain error messages, prior to commit d86e185e485b6330216dee8e854455c694e3a...
CVE-2021-34170CRITICAL9.8Bandai Namco FromSoftware Dark Souls III allows remote attackers to execute arbitrary code.
CVE-2021-33622CRITICAL9.8Sylabs Singularity 3.5.x and 3.6.x, and SingularityPRO before 3.5-8, has an Incorrect Check of a Function's Return Value...
CVE-2021-27388CRITICAL9.8SINAMICS medium voltage routable products are affected by a vulnerability in the Sm@rtServer component for remote access...
CVE-2021-0324CRITICAL9.8Product: AndroidVersions: Android SoCAndroid ID: A-175402462
CVE-2021-32682CRITICAL9.8elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect e...
CVE-2021-23394CRITICAL9.8The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in ...
CVE-2021-21382CRITICAL9.6Restund is an open source NAT traversal server. The restund TURN server can be instructed to open a relay to the loopbac...
CVE-2021-27200CRITICAL9.8In WoWonder 3.0.4, remote attackers can take over any account due to the weak cryptographic algorithm in recover.php. Th...
CVE-2021-32930CRITICAL9.8The affected product’s configuration is vulnerable due to missing authentication, which may allow an attacker to change ...
CVE-2021-27410CRITICAL9.8The affected product is vulnerable to an out-of-bounds write, which may result in corruption of data or code execution o...
CVE-2021-21833CRITICAL9.8An improper array index validation vulnerability exists in the TIF IP_planar_raster_unpack functionality of Accusoft Ima...
CVE-2021-21824CRITICAL9.8An out-of-bounds write vulnerability exists in the JPG Handle_JPEG420 functionality of Accusoft ImageGear 19.9. A specia...
CVE-2021-21795CRITICAL9.8A heap-based buffer overflow vulnerability exists in the PSD read_icc_icCurve_data functionality of Accusoft ImageGear 1...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now