2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2021-27480CRITICAL9.8Delta Industrial Automation COMMGR Versions 1.12 and prior are vulnerable to a stack-based buffer overflow, which may al...
CVE-2021-31646CRITICAL9.8Gestsup before 3.2.10 allows account takeover through the password recovery functionality (remote). The affected compone...
CVE-2021-29475CRITICAL10HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbi...
CVE-2021-21226CRITICAL9.6Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the re...
CVE-2021-21223CRITICAL9.6Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the render...
CVE-2021-21201CRITICAL9.6Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the r...
CVE-2021-25839CRITICAL9.8A weak password requirement vulnerability exists in the Create New User function of MintHCM RELEASE 3.0.8, which could l...
CVE-2021-26797CRITICAL9.8An access control vulnerability in Hame SD1 Wi-Fi firmware <=V.20140224154640 allows an attacker to get system administr...
CVE-2021-25928CRITICAL9.8Prototype pollution vulnerability in 'safe-obj' versions 1.0.0 through 1.0.2 allows an attacker to cause a denial of ser...
CVE-2021-25927CRITICAL9.8Prototype pollution vulnerability in 'safe-flat' versions 2.0.0 through 2.0.1 allows an attacker to cause a denial of se...
CVE-2021-23365CRITICAL9.1The package github.com/tyktechnologies/tyk-identity-broker before 1.1.1 are vulnerable to Authentication Bypass via the ...
CVE-2021-20711CRITICAL9.8Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors...
CVE-2021-20697CRITICAL9.8Missing authentication for critical function in DAP-1880AC firmware version 1.21 and earlier allows a remote attacker to...
CVE-2021-31761CRITICAL9.6Webmin 1.973 is affected by reflected Cross Site Scripting (XSS) to achieve Remote Command Execution through Webmin's ru...
CVE-2021-31726CRITICAL9.8Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a pay...
CVE-2021-30502CRITICAL9.8The unofficial vscode-ghc-simple (aka Simple Glasgow Haskell Compiler) extension before 0.2.3 for Visual Studio Code all...
CVE-2021-22205CRITICAL10An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati...
CVE-2021-22893CRITICAL10Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo...
CVE-2021-26291CRITICAL9.1Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surpris...
CVE-2021-31597CRITICAL9.4The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUn...
CVE-2021-2320CRITICAL9.1Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen...
CVE-2021-2319CRITICAL9.1Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen...
CVE-2021-2318CRITICAL9.1Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen...
CVE-2021-2317CRITICAL10Vulnerability in the Oracle Cloud Infrastructure Storage Gateway product of Oracle Storage Gateway (component: Managemen...
CVE-2021-2302CRITICAL9.8Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: OPSS). Supported ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now