2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21018 | CRITICAL | 9.1 | 4.1% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command inject... |
| CVE-2021-21017 | HIGH | 8.8 | 86.2% | Feb 11, 2021 | Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e... |
| CVE-2021-21016 | CRITICAL | 9.1 | 4.7% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command inject... |
| CVE-2021-21015 | HIGH | 8 | 2.9% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command inj... |
| CVE-2021-21307 | CRITICAL | 9.8 | 89.2% | Feb 11, 2021 | Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. ... |
| CVE-2021-27191 | HIGH | 7.5 | 2.0% | Feb 11, 2021 | The get-ip-range package before 4.0.0 for Node.js is vulnerable to denial of service (DoS) if the range is untrusted inp... |
| CVE-2021-27184 | HIGH | 7.5 | 1.6% | Feb 11, 2021 | Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter en... |
| CVE-2021-25690 | HIGH | 7.5 | 1.0% | Feb 11, 2021 | A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the ... |
| CVE-2021-25689 | CRITICAL | 9.8 | 1.5% | Feb 11, 2021 | An out of bounds write in Teradici PCoIP soft client versions prior to version 20.10.1 could allow an attacker to remote... |
| CVE-2021-25688 | MEDIUM | 5.5 | 0.2% | Feb 11, 2021 | Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux... |
| CVE-2021-22881 | MEDIUM | 6.1 | 87.3% | Feb 11, 2021 | The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Sp... |
| CVE-2021-22880 | HIGH | 7.5 | 4.4% | Feb 11, 2021 | The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of ser... |
| CVE-2021-22658 | CRITICAL | 9.8 | 12.7% | Feb 11, 2021 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalat... |
| CVE-2021-22656 | HIGH | 7.5 | 3.1% | Feb 11, 2021 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to rea... |
| CVE-2021-22654 | HIGH | 7.5 | 11.8% | Feb 11, 2021 | Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attack... |
| CVE-2021-22652 | CRITICAL | 9.8 | 36.8% | Feb 11, 2021 | Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow a... |
| CVE-2021-21301 | MEDIUM | 4.3 | 0.9% | Feb 11, 2021 | Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerab... |
| CVE-2021-21299 | HIGH | 8.1 | 4.7% | Feb 11, 2021 | hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and ... |
| CVE-2021-20188 | HIGH | 7 | 0.3% | Feb 11, 2021 | A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not c... |
| CVE-2021-20405 | HIGH | 7.5 | 0.8% | Feb 11, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to impro... |
| CVE-2021-20404 | MEDIUM | 5.3 | 0.9% | Feb 11, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user on the network to cause a denial of service due... |
| CVE-2021-20403 | HIGH | 8.8 | 0.4% | Feb 11, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an a... |
| CVE-2021-20402 | LOW | 2.7 | 1.0% | Feb 11, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when... |
| CVE-2021-23335 | HIGH | 7.5 | 1.4% | Feb 11, 2021 | All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or... |
| CVE-2021-23334 | — | — | — | Feb 11, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now