2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3859 | HIGH | 7.5 | 1.2% | Aug 26, 2022 | A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This fl... |
| CVE-2021-3856 | MEDIUM | 4.3 | 0.9% | Aug 26, 2022 | ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classl... |
| CVE-2021-3754 | MEDIUM | 5.3 | 1.8% | Aug 26, 2022 | A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any... |
| CVE-2021-3735 | MEDIUM | 4.4 | 0.2% | Aug 26, 2022 | A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while ... |
| CVE-2021-3703 | HIGH | 7.5 | 0.7% | Aug 26, 2022 | It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA... |
| CVE-2021-3691 | — | — | — | Aug 26, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-3688 | MEDIUM | 4.8 | 0.5% | Aug 26, 2022 | A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the pa... |
| CVE-2021-3669 | MEDIUM | 5.5 | 0.3% | Aug 26, 2022 | A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segme... |
| CVE-2021-3651 | — | — | — | Aug 26, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-3644 | LOW | 3.3 | 0.7% | Aug 26, 2022 | A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contai... |
| CVE-2021-3632 | HIGH | 7.5 | 0.9% | Aug 26, 2022 | A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is no... |
| CVE-2021-3627 | — | — | — | Aug 26, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-3585 | MEDIUM | 5.5 | 0.2% | Aug 26, 2022 | A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deploymen... |
| CVE-2021-3574 | LOW | 3.3 | 0.4% | Aug 26, 2022 | A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects... |
| CVE-2021-3563 | HIGH | 7.4 | 1.3% | Aug 26, 2022 | A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing atta... |
| CVE-2021-3427 | MEDIUM | 6.1 | 0.7% | Aug 26, 2022 | The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly s... |
| CVE-2021-3414 | HIGH | 8.1 | 0.5% | Aug 26, 2022 | A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a... |
| CVE-2021-35939 | MEDIUM | 6.7 | 0.5% | Aug 26, 2022 | It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the par... |
| CVE-2021-20260 | HIGH | 7.8 | 0.2% | Aug 26, 2022 | A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated ... |
| CVE-2021-40285 | HIGH | 8.1 | 0.8% | Aug 26, 2022 | htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php... |
| CVE-2021-39394 | MEDIUM | 6.5 | 0.3% | Aug 26, 2022 | mm-wiki v0.2.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add u... |
| CVE-2021-39393 | MEDIUM | 6.1 | 0.5% | Aug 26, 2022 | mm-wiki v0.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the markdown editor. |
| CVE-2021-3020 | HIGH | 8.8 | 1.0% | Aug 26, 2022 | An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (buil... |
| CVE-2021-32570 | MEDIUM | 4.9 | 0.7% | Aug 26, 2022 | In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retriev... |
| CVE-2021-43329 | CRITICAL | 9.8 | 2.3% | Aug 25, 2022 | A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attac... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now