2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27480 | CRITICAL | 9.8 | 1.3% | Apr 27, 2021 | Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may al... |
| CVE-2021-31646 | CRITICAL | 9.8 | 1.3% | Apr 26, 2021 | Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected compone... |
| CVE-2021-29475 | CRITICAL | 10 | 1.2% | Apr 26, 2021 | HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbi... |
| CVE-2021-21226 | CRITICAL | 9.6 | 1.4% | Apr 26, 2021 | Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the re... |
| CVE-2021-21223 | CRITICAL | 9.6 | 1.4% | Apr 26, 2021 | Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the render... |
| CVE-2021-21201 | CRITICAL | 9.6 | 1.7% | Apr 26, 2021 | Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the r... |
| CVE-2021-25839 | CRITICAL | 9.8 | 1.2% | Apr 26, 2021 | A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could l... |
| CVE-2021-26797 | CRITICAL | 9.8 | 1.4% | Apr 26, 2021 | An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administr... |
| CVE-2021-25928 | CRITICAL | 9.8 | 3.3% | Apr 26, 2021 | Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of ser... |
| CVE-2021-25927 | CRITICAL | 9.8 | 3.3% | Apr 26, 2021 | Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of se... |
| CVE-2021-23365 | CRITICAL | 9.1 | 1.0% | Apr 26, 2021 | The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the ... |
| CVE-2021-20711 | CRITICAL | 9.8 | 1.4% | Apr 26, 2021 | Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors... |
| CVE-2021-20697 | CRITICAL | 9.8 | 1.7% | Apr 26, 2021 | Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to... |
| CVE-2021-31761 | CRITICAL | 9.6 | 33.6% | Apr 25, 2021 | Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's ru... |
| CVE-2021-31726 | CRITICAL | 9.8 | 1.8% | Apr 25, 2021 | Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a pay... |
| CVE-2021-30502 | CRITICAL | 9.8 | 2.9% | Apr 25, 2021 | The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code all... |
| CVE-2021-22205 | CRITICAL | 10 | 99.7% | Apr 23, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati... |
| CVE-2021-22893 | CRITICAL | 10 | 47.2% | Apr 23, 2021 | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo... |
| CVE-2021-26291 | CRITICAL | 9.1 | 8.7% | Apr 23, 2021 | Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surpris... |
| CVE-2021-31597 | CRITICAL | 9.4 | 2.1% | Apr 23, 2021 | The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUn... |
| CVE-2021-2320 | CRITICAL | 9.1 | 1.1% | Apr 22, 2021 | Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen... |
| CVE-2021-2319 | CRITICAL | 9.1 | 1.1% | Apr 22, 2021 | Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen... |
| CVE-2021-2318 | CRITICAL | 9.1 | 1.1% | Apr 22, 2021 | Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen... |
| CVE-2021-2317 | CRITICAL | 10 | 1.9% | Apr 22, 2021 | Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen... |
| CVE-2021-2302 | CRITICAL | 9.8 | 5.7% | Apr 22, 2021 | Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now