2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1070 | HIGH | 7.1 | 0.3% | Jan 26, 2021 | NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, L4T versions prior to 32.5, contains a v... |
| CVE-2021-3309 | HIGH | 8.1 | 1.7% | Jan 26, 2021 | packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by t... |
| CVE-2021-3156 | HIGH | 7.8 | 99.3% | Jan 26, 2021 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege... |
| CVE-2021-26272 | MEDIUM | 6.5 | 2.2% | Jan 26, 2021 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL... |
| CVE-2021-26271 | MEDIUM | 6.5 | 2.0% | Jan 26, 2021 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted tex... |
| CVE-2021-21283 | MEDIUM | 5.4 | 0.8% | Jan 26, 2021 | Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.... |
| CVE-2021-21278 | CRITICAL | 9.8 | 1.6% | Jan 26, 2021 | RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic... |
| CVE-2021-21271 | MEDIUM | 6.5 | 1.7% | Jan 26, 2021 | Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - writ... |
| CVE-2021-3308 | MEDIUM | 5.5 | 0.4% | Jan 26, 2021 | An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through d... |
| CVE-2021-22159 | HIGH | 7.8 | 0.3% | Jan 26, 2021 | Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Managemen... |
| CVE-2021-23272 | MEDIUM | 5.4 | 0.5% | Jan 26, 2021 | The Application Development Clients component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Dis... |
| CVE-2021-3304 | CRITICAL | 9.8 | 1.3% | Jan 26, 2021 | Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI. |
| CVE-2021-3297 | HIGH | 7.8 | 20.5% | Jan 26, 2021 | On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access. |
| CVE-2021-3291 | HIGH | 7.2 | 16.8% | Jan 26, 2021 | Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod... |
| CVE-2021-3286 | CRITICAL | 9.8 | 1.0% | Jan 26, 2021 | SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variati... |
| CVE-2021-3285 | MEDIUM | 5.3 | 1.1% | Jan 26, 2021 | jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS. |
| CVE-2021-3278 | CRITICAL | 9.8 | 25.3% | Jan 26, 2021 | Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection ... |
| CVE-2021-3223 | HIGH | 7.5 | 16.5% | Jan 26, 2021 | Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files. |
| CVE-2021-3199 | CRITICAL | 9.8 | 8.2% | Jan 26, 2021 | Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT... |
| CVE-2021-3195 | HIGH | 7.5 | 1.2% | Jan 26, 2021 | bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin di... |
| CVE-2021-3193 | CRITICAL | 9.8 | 9.8% | Jan 26, 2021 | Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7... |
| CVE-2021-3190 | CRITICAL | 9.8 | 5.3% | Jan 26, 2021 | The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by... |
| CVE-2021-3188 | CRITICAL | 9.8 | 1.8% | Jan 26, 2021 | phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports. |
| CVE-2021-3186 | MEDIUM | 5.4 | 2.5% | Jan 26, 2021 | A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m... |
| CVE-2021-3185 | CRITICAL | 9.8 | 2.4% | Jan 26, 2021 | A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now