2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-1573HIGH7.5A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Th...
CVE-2021-38991HIGH7.8IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore com...
CVE-2021-45460HIGH8.1A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted reg...
CVE-2021-45034HIGH7.5A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER ...
CVE-2021-45033HIGH8.8A vulnerability has been identified in CP-8000 MASTER MODULE WITH I/O -25/+70°C (All versions < V16.20), CP-8000 MASTER ...
CVE-2021-41769HIGH7.5A vulnerability has been identified in SIPROTEC 5 6MD85 devices (CPU variant CP300) (All versions < V8.83), SIPROTEC 5 6...
CVE-2021-37198HIGH8.8A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers...
CVE-2021-37197HIGH8.8A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers...
CVE-2021-36414HIGH7.8A heab-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via media.c, which allows attackers to cause a...
CVE-2021-36412HIGH7.8A heap-based buffer overflow vulnerability exists in MP4Box in GPAC 1.0.1 via the gp_rtp_builder_do_mpeg12_video functio...
CVE-2021-36409HIGH7.8There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file,...
CVE-2021-29454HIGH8.8Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio...
CVE-2021-21408HIGH8.8Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prio...
CVE-2021-25054HIGH8.8The WPcalc WordPress plugin through 2.1 does not sanitize user input into the 'did' parameter and uses it in a SQL state...
CVE-2021-25053HIGH8.8The WP Coder WordPress plugin before 2.5.2 within the wow-company admin menu page allows to include() arbitrary file wit...
CVE-2021-25052HIGH8.8The Button Generator WordPress plugin before 2.3.3 within the wow-company admin menu page allows to include() arbitrary ...
CVE-2021-25051HIGH8.8The Modal Window WordPress plugin before 5.2.2 within the wow-company admin menu page allows to include() arbitrary file...
CVE-2021-24948HIGH7.5The Plus Addons for Elementor - Pro WordPress plugin before 5.0.7 does not validate the qvquery parameter of the tp_get_...
CVE-2021-24862HIGH7.2The RegistrationMagic WordPress plugin before 5.0.1.6 does not escape user input in its rm_chronos_ajax AJAX action befo...
CVE-2021-23218HIGH7.5When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could b...
CVE-2021-23154HIGH7.8In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided argu...
CVE-2021-44586HIGH7.5An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that ...
CVE-2021-46165HIGH7.8Zoho ManageEngine Desktop Central before 10.0.662, during startup, launches an executable file from the batch files, but...
CVE-2021-46164HIGH8.8Zoho ManageEngine Desktop Central before 10.0.662 allows remote code execution by an authenticated user who has complete...
CVE-2021-46149HIGH7.5An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. A denial of service ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now