2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3859HIGH7.5A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This fl...
CVE-2021-3856MEDIUM4.3ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classl...
CVE-2021-3754MEDIUM5.3A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any...
CVE-2021-3735MEDIUM4.4A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while ...
CVE-2021-3703HIGH7.5It was found that the CVE-2021-27918, CVE-2021-31525 and CVE-2021-33196 have been incorrectly mentioned as fixed in RHSA...
CVE-2021-3691Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-3688MEDIUM4.8A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the pa...
CVE-2021-3669MEDIUM5.5A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segme...
CVE-2021-3651Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-3644LOW3.3A flaw was found in wildfly-core in all versions. If a vault expression is in the form of a single attribute that contai...
CVE-2021-3632HIGH7.5A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is no...
CVE-2021-3627Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-3585MEDIUM5.5A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deploymen...
CVE-2021-3574LOW3.3A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects...
CVE-2021-3563HIGH7.4A flaw was found in openstack-keystone. Only the first 72 characters of an application secret are verified allowing atta...
CVE-2021-3427MEDIUM6.1The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly s...
CVE-2021-3414HIGH8.1A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a...
CVE-2021-35939MEDIUM6.7It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the par...
CVE-2021-20260HIGH7.8A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated ...
CVE-2021-40285HIGH8.1htmly v2.8.1 was discovered to contain an arbitrary file deletion vulnerability via the component \views\backup.html.php...
CVE-2021-39394MEDIUM6.5mm-wiki v0.2.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add u...
CVE-2021-39393MEDIUM6.1mm-wiki v0.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the markdown editor.
CVE-2021-3020HIGH8.8An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (buil...
CVE-2021-32570MEDIUM4.9In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retriev...
CVE-2021-43329CRITICAL9.8A SQL injection vulnerability in license_update.php in Mumara Classic through 2.93 allows a remote unauthenticated attac...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now