2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26472 | CRITICAL | 9.8 | 2.5% | Jun 8, 2021 | In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1 installed on Windows, the http API located at /consumerweb/... |
| CVE-2021-26471 | CRITICAL | 9.8 | 2.3% | Jun 8, 2021 | In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a comm... |
| CVE-2021-28293 | CRITICAL | 9.8 | 1.6% | Jun 8, 2021 | Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Passw... |
| CVE-2021-32673 | CRITICAL | 9.8 | 1.9% | Jun 8, 2021 | reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg... |
| CVE-2021-32671 | CRITICAL | 10 | 39.7% | Jun 7, 2021 | Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be convert... |
| CVE-2021-20699 | CRITICAL | 9.8 | 1.7% | Jun 7, 2021 | Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492... |
| CVE-2021-20698 | CRITICAL | 9.8 | 1.5% | Jun 7, 2021 | Sharp NEC Displays (UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492V... |
| CVE-2021-32198 | CRITICAL | 9.8 | 1.2% | Jun 6, 2021 | EmTec ZOC through 8.02.4 allows remote servers to cause a denial of service (Windows GUI hang) by telling the ZOC window... |
| CVE-2021-31251 | CRITICAL | 9.8 | 35.7% | Jun 4, 2021 | An authentication bypass in telnet server in BF-430 and BF431 232/422 TCP/IP Converter, BF-450M and SEMAC from CHIYU Tec... |
| CVE-2021-30475 | CRITICAL | 9.8 | 2.2% | Jun 4, 2021 | aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow. |
| CVE-2021-25947 | CRITICAL | 9.8 | 3.0% | Jun 3, 2021 | Prototype pollution vulnerability in 'nestie' versions 0.0.0 through 1.0.0 allows an attacker to cause a denial of servi... |
| CVE-2021-22333 | CRITICAL | 9.8 | 0.9% | Jun 3, 2021 | There is an Improper Validation of Array Index vulnerability in Huawei Smartphone. Successful exploitation of this vulne... |
| CVE-2021-33806 | CRITICAL | 9.8 | 3.0% | Jun 3, 2021 | The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data... |
| CVE-2021-30474 | CRITICAL | 9.8 | 1.9% | Jun 2, 2021 | aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free. |
| CVE-2021-31921 | CRITICAL | 9.8 | 1.5% | Jun 2, 2021 | Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can acc... |
| CVE-2021-25288 | CRITICAL | 9.1 | 2.3% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i. |
| CVE-2021-25287 | CRITICAL | 9.1 | 2.9% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la. |
| CVE-2021-26707 | CRITICAL | 9.8 | 1.9% | Jun 2, 2021 | The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding... |
| CVE-2021-3538 | CRITICAL | 9.8 | 2.3% | Jun 2, 2021 | A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630... |
| CVE-2021-3520 | CRITICAL | 9.8 | 3.2% | Jun 2, 2021 | There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger a... |
| CVE-2021-29089 | CRITICAL | 9.8 | 1.9% | Jun 2, 2021 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail componen... |
| CVE-2021-32654 | CRITICAL | 9.1 | 1.8% | Jun 1, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an... |
| CVE-2021-33181 | CRITICAL | 9.1 | 1.0% | Jun 1, 2021 | Server-Side Request Forgery (SSRF) vulnerability in webapi component in Synology Video Station before 2.4.10-1632 allows... |
| CVE-2021-33180 | CRITICAL | 9.8 | 1.0% | Jun 1, 2021 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in S... |
| CVE-2021-32647 | CRITICAL | 9.1 | 2.9% | Jun 1, 2021 | Emissary is a P2P based data-driven workflow engine. Affected versions of Emissary are vulnerable to post-authentication... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now