2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22850CRITICAL9.8HGiga EIP product lacks ineffective access control in certain pages that allow attackers to access database or perform p...
CVE-2021-3178MEDIUM6.5fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, all...
CVE-2021-3177CRITICAL9.8Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execu...
CVE-2021-20619MEDIUM6.1Cross-site scripting vulnerability in GROWI (v4.2 Series) versions prior to v4.2.3 allows remote attackers to inject an ...
CVE-2021-25178HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A stack-based buffer overflow vulnerability...
CVE-2021-25177HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Confusion issue exists when renderin...
CVE-2021-25176HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A NULL pointer dereference exists when rend...
CVE-2021-25175HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Conversion issue exists when renderi...
CVE-2021-25174HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory corruption vulnerability exists wh...
CVE-2021-25173HIGH7.8An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vul...
CVE-2021-25295MEDIUM6.1OpenCATS through 0.9.5-3 has multiple Cross-site Scripting (XSS) issues.
CVE-2021-25294CRITICAL9.8OpenCATS through 0.9.5-3 unsafely deserializes index.php?m=activity requests, leading to remote code execution. This occ...
CVE-2021-3166HIGH7.5An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devices. An attacker can upload arbitrary file content as a firm...
CVE-2021-3113HIGH7.5Netsia SEBA+ through 0.16.1 build 70-e669dcd7 allows remote attackers to discover session cookies via a direct /session/...
CVE-2021-3162HIGH7.8Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
CVE-2021-21251HIGH8.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3 there is a critical "zip slip" vulnerability. Th...
CVE-2021-21250MEDIUM6.5OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which may lea...
CVE-2021-21249HIGH8.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which ...
CVE-2021-21248HIGH8.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the...
CVE-2021-21247HIGH8.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the application's BasePage registers an AJAX ev...
CVE-2021-21246HIGH7.5OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a secur...
CVE-2021-21245CRITICAL9.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user control...
CVE-2021-21242CRITICAL9.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lea...
CVE-2021-21244CRITICAL9.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth ...
CVE-2021-21243CRITICAL9.8OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, a Kubernetes REST endpoint exposes two methods ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now