2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-38787HIGH7.5There is an integer overflow in the ION driver "/dev/ion" of Allwinner R818 SoC Android Q SDK V1.0 that could use the io...
CVE-2021-38786HIGH7.5There is a NULL pointer dereference in media/libcedarc/vdecoder of Allwinner R818 SoC Android Q SDK V1.0, which could ca...
CVE-2021-31854HIGH7.8A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary...
CVE-2021-34404HIGH7.6Android images for T210 provided by NVIDIA contain a vulnerability in BROM, where failure to limit access to AHB-DMA whe...
CVE-2021-34403HIGH7.8NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit...
CVE-2021-34401HIGH7.8NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where imprope...
CVE-2021-4083HIGH7A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in...
CVE-2021-43353HIGH8.8The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the...
CVE-2021-37866HIGH7.5Mattermost Boards plugin v0.10.0 and earlier fails to invalidate a session on the server-side when a user logged out of ...
CVE-2021-29632HIGH7.5In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE...
CVE-2021-41550HIGH7.2Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
CVE-2021-38696HIGH7.5SoftVibe SARABAN for INFOMA 1.1 has Incorrect Access Control vulnerability, that allows attackers to access signature fi...
CVE-2021-38785HIGH7.5There is a NULL pointer deference in the Allwinner R818 SoC Android Q SDK V1.0 camera driver /dev/cedar_dev that could u...
CVE-2021-38784HIGH7.5There is a NULL pointer dereference in the syscall open_exec function of Allwinner R818 SoC Android Q SDK V1.0 that coul...
CVE-2021-38694HIGH7.5SoftVibe SARABAN for INFOMA 1.1 allows SQL Injection.
CVE-2021-38783HIGH7.5There is a Out-of-Bound Write in the Allwinner R818 SoC Android Q SDK V1.0 camera driver "/dev/cedar_dev" through iotcl ...
CVE-2021-33965HIGH8.8China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by ...
CVE-2021-45394HIGH8.8An issue was discovered in Spipu HTML2PDF before 5.2.4. Attackers can trigger deserialization of arbitrary data via the ...
CVE-2021-33964HIGH8.8China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives ...
CVE-2021-38965HIGH8.8IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary com...
CVE-2021-4164HIGH8.8calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-25036HIGH8.8The All in One SEO WordPress plugin before 4.1.5.3 is affected by a Privilege Escalation issue, which was discovered dur...
CVE-2021-44537HIGH7.8ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading t...
CVE-2021-33828HIGH8.8The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (th...
CVE-2021-33827HIGH7.2The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now