2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27362CRITICAL9.8The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a Read Access Violation on Control Flow starting at WPG!ReadWPG_W+0...
CVE-2021-27224HIGH7.5The WPG plugin before 3.1.0.0 for IrfanView 4.57 has a user-mode write access violation starting at WPG+0x0000000000012e...
CVE-2021-26809CRITICAL9.8PHPGurukul Car Rental Project version 2.0 suffers from a remote shell upload vulnerability in changeimage1.php.
CVE-2021-26697MEDIUM5.3The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allow...
CVE-2021-26559MEDIUM6.5Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User...
CVE-2021-25780HIGH7.2An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could...
CVE-2021-25779CRITICAL9.8Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page.
CVE-2021-22174HIGH7.5Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture ...
CVE-2021-22173HIGH7.5Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted ca...
CVE-2021-22855CRITICAL9.8The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can sen...
CVE-2021-22854HIGH7.5The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtai...
CVE-2021-22853MEDIUM5.4The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access ...
CVE-2021-0109HIGH7.8Insecure inherited permissions for the Intel(R) SOC driver package for STK1A32SC before version 604 may allow an authent...
CVE-2021-22553HIGH7.5Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not ...
CVE-2021-22858HIGH8.8Attackers can access the CGE account management function without privilege for permission elevation and execute arbitrar...
CVE-2021-22857HIGH7.5The CGE page with download function contains a Directory Traversal vulnerability. Attackers can use this loophole to dow...
CVE-2021-22856HIGH7.5The CGE property management system contains SQL Injection vulnerabilities. Remote attackers can inject SQL commands into...
CVE-2021-23885HIGH8.8Privilege escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.8 allows an authenticated user to gain eleva...
CVE-2021-23339MEDIUM6.5This affects all versions before 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allow...
CVE-2021-20655HIGH7.2FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary ...
CVE-2021-20653MEDIUM5.3Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 ...
CVE-2021-26934HIGH7.8An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) ...
CVE-2021-26933MEDIUM5.5An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are byp...
CVE-2021-26932MEDIUM5.5An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in...
CVE-2021-26931MEDIUM5.5An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consid...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now