2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-26472CRITICAL9.8In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/...
CVE-2021-26471CRITICAL9.8In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a comm...
CVE-2021-28293CRITICAL9.8Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Passw...
CVE-2021-32673CRITICAL9.8reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg...
CVE-2021-32671CRITICAL10Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be convert...
CVE-2021-20699CRITICAL9.8Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492...
CVE-2021-20698CRITICAL9.8Sharp NEC Displays (UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492V...
CVE-2021-32198CRITICAL9.8EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window...
CVE-2021-31251CRITICAL9.8An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Tec...
CVE-2021-30475CRITICAL9.8aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
CVE-2021-25947CRITICAL9.8Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of servi...
CVE-2021-22333CRITICAL9.8There is an Improper Validation of Array Index vulnerability in Huawei Smartphone. Successful exploitation of this vulne...
CVE-2021-33806CRITICAL9.8The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data...
CVE-2021-30474CRITICAL9.8aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.
CVE-2021-31921CRITICAL9.8Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can acc...
CVE-2021-25288CRITICAL9.1An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.
CVE-2021-25287CRITICAL9.1An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.
CVE-2021-26707CRITICAL9.8The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding...
CVE-2021-3538CRITICAL9.8A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630...
CVE-2021-3520CRITICAL9.8There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger a...
CVE-2021-29089CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail componen...
CVE-2021-32654CRITICAL9.1Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an...
CVE-2021-33181CRITICAL9.1Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows...
CVE-2021-33180CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in S...
CVE-2021-32647CRITICAL9.1Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now