2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-36338HIGH8Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability. An adjacent malicious us...
CVE-2021-23664HIGH7.5The package @isomorphic-git/cors-proxy before 2.7.1 are vulnerable to Server-side Request Forgery (SSRF) due to missing ...
CVE-2021-23631HIGH7.5This affects all versions of package convert-svg-core; all versions of package convert-svg-to-png; all versions of packa...
CVE-2021-23460HIGH7.5The package min-dash before 3.8.1 are vulnerable to Prototype Pollution via the set method due to missing enforcement of...
CVE-2021-44593HIGH8.1Simple College Website 1.0 is vulnerable to unauthenticated file upload & remote code execution via UNION-based SQL inje...
CVE-2021-44464HIGH8.8Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 contains service credentials likely to be common across al...
CVE-2021-41835HIGH7.5Fresenius Kabi Agilia Link + version 3.0 does not enforce transport layer encryption. Therefore, transmitted data may be...
CVE-2021-33846HIGH7.2Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 issues authentication tokens to authenticat...
CVE-2021-23236HIGH7.5Requests may be used to interrupt the normal operation of the device. When exploited, Fresenius Kabi Agilia Link+ versio...
CVE-2021-46334HIGH7.8Moddable SDK v11.5.0 was discovered to contain a stack buffer overflow via the component __interceptor_strcat.
CVE-2021-46332HIGH7.8Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via xs/sources/xsDataView.c in fxUint8Getter.
CVE-2021-46328HIGH7.8Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __libc_start_main.
CVE-2021-46326HIGH7.8Moddable SDK v11.5.0 was discovered to contain a heap-buffer-overflow via the component __asan_memcpy.
CVE-2021-46325HIGH7.8Espruino 2v10.246 was discovered to contain a stack buffer overflow via src/jsutils.c in vcbprintf.
CVE-2021-46324HIGH7.8Espruino 2v11.251 was discovered to contain a stack buffer overflow via src/jsvar.c in jsvNewFromString.
CVE-2021-45417HIGH7.8AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attribut...
CVE-2021-44737HIGH8.8PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal ...
CVE-2021-43269HIGH8.8In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a maliciou...
CVE-2021-23843HIGH7.8The Bosch software tools AccessIPConfig.exe and AmcIpConfig.exe are used to configure certains settings in AMC2 devices....
CVE-2021-23842HIGH7.1Communication to the AMC2 uses a state-of-the-art cryptographic algorithm for symmetric encryption called Blowfish. An a...
CVE-2021-38789HIGH7.5Allwinner R818 SoC Android Q SDK V1.0 is affected by an incorrect access control vulnerability that does not check the c...
CVE-2021-42810HIGH7.8A flaw in the previous versions of the product may allow an authenticated attacker the ability to execute code as a priv...
CVE-2021-38788HIGH7.5The Background service in Allwinner R818 SoC Android Q SDK V1.0 is used to manage background applications. Malicious app...
CVE-2021-46104HIGH7.5An issue was discovered in webp_server_go 0.4.0. There is a directory traversal vulnerability that can read arbitrary fi...
CVE-2021-45808HIGH8.8jpress v4.2.0 allows users to register an account by default. With the account, user can upload arbitrary files to the s...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now