2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0474 | CRITICAL | 9.8 | 3.4% | Jun 11, 2021 | In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead... |
| CVE-2021-22915 | CRITICAL | 9.8 | 1.7% | Jun 11, 2021 | Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 s... |
| CVE-2021-22768 | CRITICAL | 9.8 | 2.7% | Jun 11, 2021 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ... |
| CVE-2021-22767 | CRITICAL | 9.8 | 2.7% | Jun 11, 2021 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ... |
| CVE-2021-22765 | CRITICAL | 9.8 | 2.7% | Jun 11, 2021 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ... |
| CVE-2021-22763 | CRITICAL | 9.8 | 1.8% | Jun 11, 2021 | A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic... |
| CVE-2021-22175 | CRITICAL | 9.8 | 53.4% | Jun 11, 2021 | When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab af... |
| CVE-2021-25387 | CRITICAL | 10 | 0.6% | Jun 11, 2021 | An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Relea... |
| CVE-2021-25386 | CRITICAL | 9.8 | 0.6% | Jun 11, 2021 | An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-202... |
| CVE-2021-25385 | CRITICAL | 9.8 | 0.6% | Jun 11, 2021 | An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-202... |
| CVE-2021-25384 | CRITICAL | 9.8 | 0.5% | Jun 11, 2021 | An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor libra... |
| CVE-2021-25383 | CRITICAL | 9.8 | 0.5% | Jun 11, 2021 | An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release... |
| CVE-2021-3013 | CRITICAL | 9.8 | 1.9% | Jun 11, 2021 | ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working direct... |
| CVE-2021-24035 | CRITICAL | 9.1 | 1.1% | Jun 11, 2021 | A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for... |
| CVE-2021-25949 | CRITICAL | 9.8 | 3.3% | Jun 10, 2021 | Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may ... |
| CVE-2021-25948 | CRITICAL | 9.8 | 3.3% | Jun 10, 2021 | Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of ... |
| CVE-2021-34363 | CRITICAL | 9.1 | 1.8% | Jun 10, 2021 | The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion vi... |
| CVE-2021-26691 | CRITICAL | 9.8 | 68.1% | Jun 10, 2021 | In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a ... |
| CVE-2021-33833 | CRITICAL | 9.8 | 2.9% | Jun 9, 2021 | ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAM... |
| CVE-2021-33357 | CRITICAL | 9.8 | 17.9% | Jun 9, 2021 | A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the ... |
| CVE-2021-23853 | CRITICAL | 9.8 | 0.9% | Jun 9, 2021 | In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through ... |
| CVE-2021-23847 | CRITICAL | 9.1 | 1.4% | Jun 9, 2021 | A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract s... |
| CVE-2021-33841 | CRITICAL | 9.8 | 2.2% | Jun 9, 2021 | SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker ... |
| CVE-2021-31962 | CRITICAL | 9.4 | 3.8% | Jun 8, 2021 | Kerberos AppContainer Security Feature Bypass Vulnerability |
| CVE-2021-26473 | CRITICAL | 9.8 | 1.8% | Jun 8, 2021 | In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFileP... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now