2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22686Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2021-3620MEDIUM5.5A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user cre...
CVE-2021-3609HIGH7.A flaw was found in the CAN BCM networking protocol in the Linux kernel, where a local attacker can abuse a flaw in the...
CVE-2021-3602MEDIUM5.5An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes ...
CVE-2021-45819HIGH7.8Wordline HIDCCEMonitorSVC before v5.2.4.3 contains an unquoted service path which allows attackers to escalate privilege...
CVE-2021-43774MEDIUM4.9A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to ...
CVE-2021-40637MEDIUM6.1OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript c...
CVE-2021-40636HIGH7.5OS4ED openSIS 8.0 is affected by SQL Injection in CheckDuplicateName.php, which can extract information from the databas...
CVE-2021-40635HIGH7.5OS4ED openSIS 8.0 is affected by SQL injection in ChooseCpSearch.php, ChooseRequestSearch.php. An attacker can inject a ...
CVE-2021-42950HIGH8.8Remote Code Execution (RCE) vulnerability exists in Zepl Notebooks all previous versions before October 25 2021. Users c...
CVE-2021-44343HIGH7.8David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats projec...
CVE-2021-44335HIGH7.8David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats projec...
CVE-2021-38269MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and L...
CVE-2021-38267MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3....
CVE-2021-38265MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attacker...
CVE-2021-38264MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote a...
CVE-2021-38263MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and ...
CVE-2021-4076HIGH7.5A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
CVE-2021-3772MEDIUM6.5A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through inva...
CVE-2021-3738HIGH8.8In DCE/RPC it is possible to share the handles (cookies for resource state) between multiple connections via a mechanism...
CVE-2021-3716LOW3.1A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM ...
CVE-2021-3715HIGH7.8A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the ...
CVE-2021-3677MEDIUM6.5A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default config...
CVE-2021-3667MEDIUM6.5An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePool...
CVE-2021-3658MEDIUM6.5bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it whe...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now