2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-1070HIGH7.1NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, L4T versions prior to 32.5, contains a v...
CVE-2021-3309HIGH8.1packages/wekan-ldap/server/ldap.js in Wekan before 4.87 can process connections even though they are not authorized by t...
CVE-2021-3156HIGH7.8Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege...
CVE-2021-26272MEDIUM6.5It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL...
CVE-2021-26271MEDIUM6.5It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted tex...
CVE-2021-21283MEDIUM5.4Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1....
CVE-2021-21278CRITICAL9.8RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic...
CVE-2021-21271MEDIUM6.5Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - writ...
CVE-2021-3308MEDIUM5.5An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through d...
CVE-2021-22159HIGH7.8Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Managemen...
CVE-2021-23272MEDIUM5.4The Application Development Clients component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Dis...
CVE-2021-3304CRITICAL9.8Sagemcom F@ST 3686 v2 3.495 devices have a buffer overflow via a long sessionKey to the goform/login URI.
CVE-2021-3297HIGH7.8On Zyxel NBG2105 V1.00(AAGU.2)C0 devices, setting the login cookie to 1 provides administrator access.
CVE-2021-3291HIGH7.2Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod...
CVE-2021-3286CRITICAL9.8SQL injection exists in Spotweb 1.4.9 because the notAllowedCommands protection mechanism is inadequate, e.g., a variati...
CVE-2021-3285MEDIUM5.3jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS.
CVE-2021-3278CRITICAL9.8Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection ...
CVE-2021-3223HIGH7.5Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
CVE-2021-3199CRITICAL9.8Directory traversal with remote code execution can occur in /upload in ONLYOFFICE Document Server before 5.6.3, when JWT...
CVE-2021-3195HIGH7.5bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin di...
CVE-2021-3193CRITICAL9.8Improper access and command validation in the Nagios Docker Config Wizard before 1.1.2, as used in Nagios XI through 5.7...
CVE-2021-3190CRITICAL9.8The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by...
CVE-2021-3188CRITICAL9.8phpList 3.6.0 allows CSV injection, related to the email parameter, and /lists/admin/ exports.
CVE-2021-3186MEDIUM5.4A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m...
CVE-2021-3185CRITICAL9.8A flaw was found in the gstreamer h264 component of gst-plugins-bad before v1.18.1 where when parsing a h264 header, an ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now