Skip to main content

Year archive

CVEs published in 2021

Archive summary

20,149 CVEs published in 2021 — 2,558 Critical, 8,477 High, 8,471 Medium, 643 Low, 0 Unrated.

CVE-2020-7794

Published Jan 8, 2021

This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-28468

Published Jan 8, 2021

This affects the package pwntools before 4.3.1. The shellcraft generator for affected versions of this module are vulnerable to Server-Side Template Injection (SSTI), which can le…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3025

Published Jan 8, 2021

Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-24577

Published Jan 8, 2021

An issue was discovered on D-Link DSL-2888A devices with firmware prior to AU_2.31_V1.1.47ae55. The One Touch application discloses sensitive information, such as the hashed admin…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-1055

Published Jan 8, 2021

NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which improper access control ma…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1054

Published Jan 8, 2021

NVIDIA GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape in which the software does not perf…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 19,876-19,900 of 20,149 CVEsPage 796 of 806