2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3142Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-35128. Reason: This candidate is a reservation d...
CVE-2021-26067MEDIUM5.3Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the...
CVE-2021-3331CRITICAL9.8WinSCP before 5.17.10 allows remote attackers to execute arbitrary programs when the URL handler encounters a crafted UR...
CVE-2021-3326HIGH7.5The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences i...
CVE-2021-26276MEDIUM5.3scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when pr...
CVE-2021-22655HIGH7.8Multiple out-of-bounds read issues have been identified in the way the application processes project files, allowing an ...
CVE-2021-22653HIGH7.8Multiple out-of-bounds write issues have been identified in the way the application processes project files, allowing an...
CVE-2021-22641HIGH7.8A heap-based buffer overflow issue has been identified in the way the application processes project files, allowing an a...
CVE-2021-22639HIGH7.8An uninitialized pointer issue has been identified in the way the application processes project files, allowing an attac...
CVE-2021-22637HIGH7.8Multiple stack-based buffer overflow issues have been identified in the way the application processes project files, all...
CVE-2021-3325CRITICAL9.8Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation...
CVE-2021-26118HIGH7.5While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Ap...
CVE-2021-26117HIGH7.5The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for ...
CVE-2021-25247HIGH7.8A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker...
CVE-2021-25226MEDIUM5.5A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci...
CVE-2021-25225MEDIUM5.5A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci...
CVE-2021-25224MEDIUM5.5A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci...
CVE-2021-3318MEDIUM6.1attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter.
CVE-2021-20357MEDIUM5.4IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...
CVE-2021-25312HIGH8.8HTCondor before 8.9.11 allows a user to submit a job as another user on the system, because of a flaw in the IDTOKENS au...
CVE-2021-25311CRITICAL9.9condor_credd in HTCondor before 8.9.11 allows Directory Traversal outside the SEC_CREDENTIAL_DIRECTORY_OAUTH directory, ...
CVE-2021-3272MEDIUM5.5jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid rel...
CVE-2021-3317HIGH8.8KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of ...
CVE-2021-3165HIGH8.8SmartAgent 3.1.0 allows a ViewOnly attacker to create a SuperUser account via the /#/CampaignManager/users URI.
CVE-2021-1071MEDIUM5.5NVIDIA Tegra kernel in Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, all L4T versions prior t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now