2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-0891 | HIGH | 7.5 | 0.3% | Aug 24, 2022 | An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Pro... |
| CVE-2021-0887 | MEDIUM | 5.5 | 0.1% | Aug 24, 2022 | In PVRSRVBridgeHeapCfgHeapConfigName, there is a possible leak of kernel heap content due to uninitialized data. This co... |
| CVE-2021-0698 | MEDIUM | 5.5 | 0.1% | Aug 24, 2022 | In PVRSRVBridgeHeapCfgHeapDetails, there is a possible leak of kernel heap content due to uninitialized data. This could... |
| CVE-2021-3997 | MEDIUM | 5.5 | 1.6% | Aug 23, 2022 | A flaw was found in systemd. An uncontrolled recursion in systemd-tmpfiles may lead to a denial of service at boot time ... |
| CVE-2021-3996 | MEDIUM | 5.5 | 0.6% | Aug 23, 2022 | A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmoun... |
| CVE-2021-3995 | MEDIUM | 5.5 | 0.6% | Aug 23, 2022 | A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmoun... |
| CVE-2021-3975 | MEDIUM | 6.5 | 1.2% | Aug 23, 2022 | A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is calle... |
| CVE-2021-3917 | MEDIUM | 5.5 | 0.2% | Aug 23, 2022 | A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable a... |
| CVE-2021-3905 | HIGH | 7.5 | 1.6% | Aug 23, 2022 | A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this f... |
| CVE-2021-3894 | — | — | — | Aug 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-3839 | HIGH | 7.5 | 1.3% | Aug 23, 2022 | A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inf... |
| CVE-2021-3827 | MEDIUM | 6.8 | 0.9% | Aug 23, 2022 | A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By ex... |
| CVE-2021-3800 | MEDIUM | 5.5 | 0.5% | Aug 23, 2022 | A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak content from files owned by... |
| CVE-2021-3798 | MEDIUM | 5.5 | 0.3% | Aug 23, 2022 | A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is cre... |
| CVE-2021-3771 | — | — | — | Aug 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-3764 | MEDIUM | 5.5 | 0.3% | Aug 23, 2022 | A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a den... |
| CVE-2021-3763 | MEDIUM | 4.3 | 0.6% | Aug 23, 2022 | A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access so... |
| CVE-2021-3759 | MEDIUM | 5.5 | 0.3% | Aug 23, 2022 | A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a u... |
| CVE-2021-3736 | MEDIUM | 5.5 | 0.2% | Aug 23, 2022 | A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in V... |
| CVE-2021-3724 | — | — | — | Aug 23, 2022 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-3714 | MEDIUM | 5.9 | 1.1% | Aug 23, 2022 | A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication ... |
| CVE-2021-3702 | MEDIUM | 6.3 | 0.2% | Aug 23, 2022 | A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a te... |
| CVE-2021-3701 | MEDIUM | 6.6 | 0.3% | Aug 23, 2022 | A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world... |
| CVE-2021-3690 | HIGH | 7.5 | 1.4% | Aug 23, 2022 | A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This f... |
| CVE-2021-3670 | MEDIUM | 6.5 | 1.7% | Aug 23, 2022 | MaxQueryDuration not honoured in Samba AD DC LDAP |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now