2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26930 | HIGH | 7.8 | 0.3% | Feb 17, 2021 | An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend,... |
| CVE-2021-27104 | CRITICAL | 9.8 | 56.7% | Feb 16, 2021 | Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpo... |
| CVE-2021-27103 | CRITICAL | 9.8 | 11.4% | Feb 16, 2021 | Accellion FTA 9_12_411 and earlier is affected by SSRF via a crafted POST request to wmProgressstat.html. The fixed vers... |
| CVE-2021-27102 | HIGH | 7.8 | 3.7% | Feb 16, 2021 | Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version i... |
| CVE-2021-27101 | CRITICAL | 9.8 | 6.0% | Feb 16, 2021 | Accellion FTA 9_12_370 and earlier is affected by SQL injection via a crafted Host header in a request to document_root.... |
| CVE-2021-27203 | MEDIUM | 5.5 | 0.4% | Feb 16, 2021 | In Dekart Private Disk 2.15, invalid use of the Type3 user buffer for IOCTL codes using METHOD_NEITHER results in arbitr... |
| CVE-2021-20075 | HIGH | 7.8 | 0.2% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for privilege escalation via configd. |
| CVE-2021-20074 | HIGH | 8.8 | 1.2% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows users to escape the provided command line interface and ... |
| CVE-2021-20073 | HIGH | 8.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows for cross-site request forgeries. |
| CVE-2021-20072 | HIGH | 7.2 | 1.4% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to arbitrarily access and delete files via an ... |
| CVE-2021-20071 | MEDIUM | 4.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via t... |
| CVE-2021-20070 | MEDIUM | 4.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scriptings attacks via t... |
| CVE-2021-20069 | MEDIUM | 4.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via th... |
| CVE-2021-20068 | MEDIUM | 4.8 | 0.5% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to conduct cross-site scripting attacks via th... |
| CVE-2021-20067 | MEDIUM | 5.3 | 0.8% | Feb 16, 2021 | Racom's MIDGE Firmware 4.4.40.105 contains an issue that allows attackers to view sensitive syslog events without authen... |
| CVE-2021-20066 | MEDIUM | 5.6 | 1.4% | Feb 16, 2021 | JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious we... |
| CVE-2021-27237 | MEDIUM | 4.8 | 1.0% | Feb 16, 2021 | The admin panel in BlackCat CMS 1.3.6 allows stored XSS (by an admin) via the Display Name field to backend/preferences/... |
| CVE-2021-21317 | MEDIUM | 5.3 | 2.5% | Feb 16, 2021 | uap-core in an open-source npm package which contains the core of BrowserScope's original user agent string parser. In u... |
| CVE-2021-21316 | HIGH | 7.8 | 1.0% | Feb 16, 2021 | less-openui5 is an npm package which enables building OpenUI5 themes with Less.js. In less-openui5 before version 0.10.,... |
| CVE-2021-23841 | MEDIUM | 5.9 | 7.5% | Feb 16, 2021 | The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer... |
| CVE-2021-23840 | HIGH | 7.5 | 50.7% | Feb 16, 2021 | Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases... |
| CVE-2021-23839 | LOW | 3.7 | 3.0% | Feb 16, 2021 | OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both S... |
| CVE-2021-21315 | HIGH | 7.8 | 90.2% | Feb 16, 2021 | The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions t... |
| CVE-2021-20987 | HIGH | 8.6 | 1.1% | Feb 16, 2021 | A denial of service and memory corruption vulnerability was found in Hilscher EtherNet/IP Core V2 prior to V2.13.0.21tha... |
| CVE-2021-20986 | HIGH | 7.5 | 1.0% | Feb 16, 2021 | A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may l... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now