2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-20487CRITICAL9.1IBM Power9 Self Boot Engine(SBE) could allow a privileged user to inject malicious code and compromise the integrity of ...
CVE-2021-25945CRITICAL9.8Prototype pollution vulnerability in 'js-extend' versions 0.0.1 through 1.0.1 allows attacker to cause a denial of servi...
CVE-2021-21986CRITICAL9.8The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the Virtual SAN Health Che...
CVE-2021-21985CRITICAL9.8The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual...
CVE-2021-22160CRITICAL9.8If Apache Pulsar is configured to authenticate clients using tokens based on JSON Web Tokens (JWT), the signature of the...
CVE-2021-33575CRITICAL9.8The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documen...
CVE-2021-33574CRITICAL9.8The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the noti...
CVE-2021-25946CRITICAL9.8Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of s...
CVE-2021-25944CRITICAL9.8Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of s...
CVE-2021-21658CRITICAL9.1Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2021-30194CRITICAL9.1CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
CVE-2021-30193CRITICAL9.8CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
CVE-2021-30192CRITICAL9.8CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
CVE-2021-30190CRITICAL9.8CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
CVE-2021-30189CRITICAL9.8CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
CVE-2021-30188CRITICAL9.8CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
CVE-2021-30108CRITICAL9.1Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Refer...
CVE-2021-29300CRITICAL9.8The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote a...
CVE-2021-20426CRITICAL9.8IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for i...
CVE-2021-32075CRITICAL9.8Re-Logic Terraria before 1.4.2.3 performs Insecure Deserialization.
CVE-2021-33497CRITICAL9.1Dutchcoders transfer.sh before 1.2.4 allows Directory Traversal for deleting files.
CVE-2021-33514CRITICAL9.8Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/li...
CVE-2021-33509CRITICAL9.9Plone through 5.2.4 allows remote authenticated managers to perform disk I/O via crafted keyword arguments to the ReStru...
CVE-2021-31474CRITICAL9.8This vulnerability allows remote attackers to execute arbitrary code on affected installations of SolarWinds Network Per...
CVE-2021-27459CRITICAL9.8A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the af...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now