2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-4112 | HIGH | 8.8 | 0.2% | Aug 25, 2022 | A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows... |
| CVE-2021-3979 | MEDIUM | 6.5 | 0.4% | Aug 25, 2022 | A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly... |
| CVE-2021-3929 | HIGH | 8.2 | 0.6% | Aug 25, 2022 | A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021... |
| CVE-2021-3914 | MEDIUM | 6.1 | 0.4% | Aug 25, 2022 | It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could... |
| CVE-2021-35938 | MEDIUM | 6.7 | 0.5% | Aug 25, 2022 | A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing... |
| CVE-2021-35937 | MEDIUM | 6.4 | 0.3% | Aug 25, 2022 | A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that... |
| CVE-2021-33844 | MEDIUM | 5.5 | 0.5% | Aug 25, 2022 | A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacke... |
| CVE-2021-23210 | MEDIUM | 5.5 | 0.4% | Aug 25, 2022 | A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An atta... |
| CVE-2021-23172 | MEDIUM | 5.5 | 0.4% | Aug 25, 2022 | A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulner... |
| CVE-2021-23159 | MEDIUM | 5.5 | 0.5% | Aug 25, 2022 | A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. ... |
| CVE-2021-20224 | MEDIUM | 5.5 | 0.4% | Aug 25, 2022 | An integer overflow issue was discovered in ImageMagick's ExportIndexQuantum() function in MagickCore/quantum-export.c. ... |
| CVE-2021-20223 | — | — | — | Aug 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-4141 | — | — | — | Aug 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-4042 | — | — | — | Aug 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-4022 | MEDIUM | 5.5 | 0.3% | Aug 25, 2022 | A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted... |
| CVE-2021-43767 | MEDIUM | 5.9 | 0.4% | Aug 25, 2022 | Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreS... |
| CVE-2021-43766 | HIGH | 8.1 | 0.5% | Aug 25, 2022 | Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common N... |
| CVE-2021-42523 | HIGH | 7.5 | 0.8% | Aug 25, 2022 | There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src... |
| CVE-2021-42522 | HIGH | 7.5 | 0.7% | Aug 25, 2022 | There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was ca... |
| CVE-2021-42521 | HIGH | 7.5 | 1.1% | Aug 25, 2022 | There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. T... |
| CVE-2021-20301 | — | — | — | Aug 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-20287 | — | — | — | Aug 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-20258 | — | — | — | Aug 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-20192 | — | — | — | Aug 25, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-25642 | HIGH | 8.8 | 1.8% | Aug 25, 2022 | ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now