2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-1910 | CRITICAL | 9.8 | 0.6% | May 7, 2021 | Double free in video due to lack of input buffer length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connect... |
| CVE-2021-32090 | CRITICAL | 9.8 | 2.1% | May 7, 2021 | The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the funct... |
| CVE-2021-32099 | CRITICAL | 9.8 | 11.4% | May 7, 2021 | A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attac... |
| CVE-2021-32098 | CRITICAL | 9.8 | 2.5% | May 7, 2021 | Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization. |
| CVE-2021-31737 | CRITICAL | 9.8 | 3.9% | May 6, 2021 | emlog v5.3.1 and emlog v6.0.0 have a Remote Code Execution vulnerability due to upload of database backup file in admin/... |
| CVE-2021-29203 | CRITICAL | 9.8 | 68.3% | May 6, 2021 | A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infr... |
| CVE-2021-28152 | CRITICAL | 9.8 | 5.2% | May 6, 2021 | Hongdian H8922 3.0.5 devices have an undocumented feature that allows access to a shell as a superuser. To connect, the ... |
| CVE-2021-32030 | CRITICAL | 9.8 | 99.4% | May 6, 2021 | The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 ... |
| CVE-2021-30473 | CRITICAL | 9.8 | 2.1% | May 6, 2021 | aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap. |
| CVE-2021-20204 | CRITICAL | 9.8 | 2.2% | May 6, 2021 | A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously cra... |
| CVE-2021-29921 | CRITICAL | 9.8 | 6.8% | May 6, 2021 | In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. ... |
| CVE-2021-24236 | CRITICAL | 9.8 | 7.1% | May 6, 2021 | The Imagements WordPress plugin through 1.2.5 allows images to be uploaded in comments, however only checks for the Cont... |
| CVE-2021-21505 | CRITICAL | 9.8 | 2.4% | May 6, 2021 | Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC ac... |
| CVE-2021-1498 | CRITICAL | 9.8 | 100.0% | May 6, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, rem... |
| CVE-2021-1497 | CRITICAL | 9.8 | 99.9% | May 6, 2021 | Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, rem... |
| CVE-2021-1468 | CRITICAL | 9.8 | 2.0% | May 6, 2021 | Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arb... |
| CVE-2021-32055 | CRITICAL | 9.1 | 2.6% | May 5, 2021 | Mutt 1.11.0 through 2.0.x before 2.0.7 (and NeoMutt 2019-10-25 through 2021-05-04) has a $imap_qresync issue in which im... |
| CVE-2021-31800 | CRITICAL | 9.8 | 19.3% | May 5, 2021 | Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a... |
| CVE-2021-23383 | CRITICAL | 9.8 | 4.5% | May 4, 2021 | The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to co... |
| CVE-2021-32020 | CRITICAL | 9.8 | 1.3% | May 3, 2021 | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memo... |
| CVE-2021-29369 | CRITICAL | 9.8 | 1.8% | May 3, 2021 | The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot command... |
| CVE-2021-28860 | CRITICAL | 9.1 | 2.0% | May 3, 2021 | In Node.js mixme, prior to v0.5.1, an attacker can add or alter properties of an object via '__proto__' through the muta... |
| CVE-2021-21507 | CRITICAL | 9.8 | 0.5% | Apr 30, 2021 | Dell EMC Networking X-Series firmware versions prior to 3.0.1.8 and Dell EMC PowerEdge VRTX Switch Module firmware versi... |
| CVE-2021-28959 | CRITICAL | 9.8 | 16.9% | Apr 30, 2021 | Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a... |
| CVE-2021-31873 | CRITICAL | 9.8 | 2.1% | Apr 30, 2021 | An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now