2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20487 | CRITICAL | 9.1 | 0.7% | May 26, 2021 | IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of ... |
| CVE-2021-25945 | CRITICAL | 9.8 | 3.0% | May 26, 2021 | Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of servi... |
| CVE-2021-21986 | CRITICAL | 9.8 | 12.9% | May 26, 2021 | The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Che... |
| CVE-2021-21985 | CRITICAL | 9.8 | 100.0% | May 26, 2021 | The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual... |
| CVE-2021-22160 | CRITICAL | 9.8 | 52.9% | May 26, 2021 | If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the... |
| CVE-2021-33575 | CRITICAL | 9.8 | 2.6% | May 25, 2021 | The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documen... |
| CVE-2021-33574 | CRITICAL | 9.8 | 2.9% | May 25, 2021 | The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the noti... |
| CVE-2021-25946 | CRITICAL | 9.8 | 3.3% | May 25, 2021 | Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of s... |
| CVE-2021-25944 | CRITICAL | 9.8 | 3.0% | May 25, 2021 | Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of s... |
| CVE-2021-21658 | CRITICAL | 9.1 | 1.5% | May 25, 2021 | Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2021-30194 | CRITICAL | 9.1 | 1.2% | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read. |
| CVE-2021-30193 | CRITICAL | 9.8 | 1.2% | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write. |
| CVE-2021-30192 | CRITICAL | 9.8 | 1.2% | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check. |
| CVE-2021-30190 | CRITICAL | 9.8 | 1.4% | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control. |
| CVE-2021-30189 | CRITICAL | 9.8 | 1.3% | May 25, 2021 | CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow. |
| CVE-2021-30188 | CRITICAL | 9.8 | 1.3% | May 25, 2021 | CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. |
| CVE-2021-30108 | CRITICAL | 9.1 | 1.1% | May 24, 2021 | Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Refer... |
| CVE-2021-29300 | CRITICAL | 9.8 | 4.5% | May 24, 2021 | The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote a... |
| CVE-2021-20426 | CRITICAL | 9.8 | 1.0% | May 24, 2021 | IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i... |
| CVE-2021-32075 | CRITICAL | 9.8 | 1.8% | May 24, 2021 | Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization. |
| CVE-2021-33497 | CRITICAL | 9.1 | 2.0% | May 24, 2021 | Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files. |
| CVE-2021-33514 | CRITICAL | 9.8 | 8.8% | May 21, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/li... |
| CVE-2021-33509 | CRITICAL | 9.9 | 2.0% | May 21, 2021 | Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStru... |
| CVE-2021-31474 | CRITICAL | 9.8 | 94.4% | May 21, 2021 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Per... |
| CVE-2021-27459 | CRITICAL | 9.8 | 1.8% | May 20, 2021 | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the af... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now