2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-1910CRITICAL9.8Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect...
CVE-2021-32090CRITICAL9.8The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the funct...
CVE-2021-32099CRITICAL9.8A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attac...
CVE-2021-32098CRITICAL9.8Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
CVE-2021-31737CRITICAL9.8emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/...
CVE-2021-29203CRITICAL9.8A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infr...
CVE-2021-28152CRITICAL9.8Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the ...
CVE-2021-32030CRITICAL9.8The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 ...
CVE-2021-30473CRITICAL9.8aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
CVE-2021-20204CRITICAL9.8A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously cra...
CVE-2021-29921CRITICAL9.8In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. ...
CVE-2021-24236CRITICAL9.8The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Cont...
CVE-2021-21505CRITICAL9.8Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC ac...
CVE-2021-1498CRITICAL9.8Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, rem...
CVE-2021-1497CRITICAL9.8Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, rem...
CVE-2021-1468CRITICAL9.8Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb...
CVE-2021-32055CRITICAL9.1Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which im...
CVE-2021-31800CRITICAL9.8Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a...
CVE-2021-23383CRITICAL9.8The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to co...
CVE-2021-32020CRITICAL9.8The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memo...
CVE-2021-29369CRITICAL9.8The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot command...
CVE-2021-28860CRITICAL9.1In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the muta...
CVE-2021-21507CRITICAL9.8Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versi...
CVE-2021-28959CRITICAL9.8Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a...
CVE-2021-31873CRITICAL9.8An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now