2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-4112HIGH8.8A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows...
CVE-2021-3979MEDIUM6.5A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly...
CVE-2021-3929HIGH8.2A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021...
CVE-2021-3914MEDIUM6.1It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could...
CVE-2021-35938MEDIUM6.7A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing...
CVE-2021-35937MEDIUM6.4A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that...
CVE-2021-33844MEDIUM5.5A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacke...
CVE-2021-23210MEDIUM5.5A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An atta...
CVE-2021-23172MEDIUM5.5A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulner...
CVE-2021-23159MEDIUM5.5A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. ...
CVE-2021-20224MEDIUM5.5An integer overflow issue was discovered in ImageMagick's ExportIndexQuantum() function in MagickCore/quantum-export.c. ...
CVE-2021-20223Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-4141Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-4042Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-4022MEDIUM5.5A vulnerability was found in rizin. The bug involves an ELF64 binary for the HPPA architecture. When a specially crafted...
CVE-2021-43767MEDIUM5.9Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreS...
CVE-2021-43766HIGH8.1Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common N...
CVE-2021-42523HIGH7.5There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src...
CVE-2021-42522HIGH7.5There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was ca...
CVE-2021-42521HIGH7.5There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. T...
CVE-2021-20301Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-20287Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-20258Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-20192Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-25642HIGH8.8ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now