2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21018CRITICAL9.1Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command inject...
CVE-2021-21017HIGH8.8Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e...
CVE-2021-21016CRITICAL9.1Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command inject...
CVE-2021-21015HIGH8Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command inj...
CVE-2021-21307CRITICAL9.8Lucee Server is a dynamic, Java based (JSR-223), tag and scripting language used for rapid web application development. ...
CVE-2021-27191HIGH7.5The get-ip-range package before 4.0.0 for Node.js is vulnerable to denial of service (DoS) if the range is untrusted inp...
CVE-2021-27184HIGH7.5Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter en...
CVE-2021-25690HIGH7.5A null pointer dereference in Teradici PCoIP Soft Client versions prior to 20.07.3 could allow an attacker to crash the ...
CVE-2021-25689CRITICAL9.8An out of bounds write in Teradici PCoIP soft client versions prior to version 20.10.1 could allow an attacker to remote...
CVE-2021-25688MEDIUM5.5Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux...
CVE-2021-22881MEDIUM6.1The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Sp...
CVE-2021-22880HIGH7.5The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of ser...
CVE-2021-22658CRITICAL9.8Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an attacker to escalat...
CVE-2021-22656HIGH7.5Advantech iView versions prior to v5.7.03.6112 are vulnerable to directory traversal, which may allow an attacker to rea...
CVE-2021-22654HIGH7.5Advantech iView versions prior to v5.7.03.6112 are vulnerable to a SQL injection, which may allow an unauthorized attack...
CVE-2021-22652CRITICAL9.8Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow a...
CVE-2021-21301MEDIUM4.3Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerab...
CVE-2021-21299HIGH8.1hyper is an open-source HTTP library for Rust (crates.io). In hyper from version 0.12.0 and before versions 0.13.10 and ...
CVE-2021-20188HIGH7A flaw was found in podman before 1.7.0. File permissions for non-root users running in a privileged container are not c...
CVE-2021-20405HIGH7.5IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized activities due to impro...
CVE-2021-20404MEDIUM5.3IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user on the network to cause a denial of service due...
CVE-2021-20403HIGH8.8IBM Security Verify Information Queue 1.0.6 and 1.0.7 is vulnerable to cross-site request forgery which could allow an a...
CVE-2021-20402LOW2.7IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when...
CVE-2021-23335HIGH7.5All versions of package is-user-valid are vulnerable to LDAP Injection which can lead to either authentication bypass or...
CVE-2021-23334Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now