2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-0474CRITICAL9.8In avrc_msg_cback of avrc_api.cc, there is a possible out of bounds write due to a heap buffer overflow. This could lead...
CVE-2021-22915CRITICAL9.8Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 s...
CVE-2021-22768CRITICAL9.8A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ...
CVE-2021-22767CRITICAL9.8A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ...
CVE-2021-22765CRITICAL9.8A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic ...
CVE-2021-22763CRITICAL9.8A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic...
CVE-2021-22175CRITICAL9.8When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab af...
CVE-2021-25387CRITICAL10An improper input validation vulnerability in sflacfd_get_frm() in libsflacextractor library prior to SMR MAY-2021 Relea...
CVE-2021-25386CRITICAL9.8An improper input validation vulnerability in sdfffd_parse_chunk_FVER() in libsdffextractor library prior to SMR MAY-202...
CVE-2021-25385CRITICAL9.8An improper input validation vulnerability in sdfffd_parse_chunk_PROP() in libsdffextractor library prior to SMR MAY-202...
CVE-2021-25384CRITICAL9.8An improper input validation vulnerability in sdfffd_parse_chunk_PROP() with Sample Rate Chunk in libsdffextractor libra...
CVE-2021-25383CRITICAL9.8An improper input validation vulnerability in scmn_mfal_read() in libsapeextractor library prior to SMR MAY-2021 Release...
CVE-2021-3013CRITICAL9.8ripgrep before 13 on Windows allows attackers to trigger execution of arbitrary programs from the current working direct...
CVE-2021-24035CRITICAL9.1A lack of filename validation when unzipping archives prior to WhatsApp for Android v2.21.8.13 and WhatsApp Business for...
CVE-2021-25949CRITICAL9.8Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may ...
CVE-2021-25948CRITICAL9.8Prototype pollution vulnerability in 'expand-hash' versions 0.1.0 through 1.0.1 allows an attacker to cause a denial of ...
CVE-2021-34363CRITICAL9.1The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion vi...
CVE-2021-26691CRITICAL9.8In Apache HTTP Server versions 2.4.0 to 2.4.46 a specially crafted SessionHeader sent by an origin server could cause a ...
CVE-2021-33833CRITICAL9.8ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAM...
CVE-2021-33357CRITICAL9.8A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the ...
CVE-2021-23853CRITICAL9.8In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through ...
CVE-2021-23847CRITICAL9.1A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract s...
CVE-2021-33841CRITICAL9.8SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker ...
CVE-2021-31962CRITICAL9.4Kerberos AppContainer Security Feature Bypass Vulnerability
CVE-2021-26473CRITICAL9.8In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 the http API located at /sgwebservice_o.php action logFileP...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now