2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26474 | HIGH | 8.8 | 0.7% | Jun 8, 2021 | Various Vembu products allow an attacker to execute a (non-blind) http-only Cross Site Request Forgery (Other products o... |
| CVE-2021-33571 | HIGH | 7.5 | 3.1% | Jun 8, 2021 | In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_... |
| CVE-2021-32674 | HIGH | 8.8 | 1.6% | Jun 8, 2021 | Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefou... |
| CVE-2021-34280 | HIGH | 7.8 | 1.3% | Jun 8, 2021 | Polaris Office v9.103.83.44230 is affected by a Uninitialized Pointer Vulnerability in PolarisOffice.exe and EngineDLL.d... |
| CVE-2021-33176 | HIGH | 7.5 | 1.1% | Jun 8, 2021 | VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memor... |
| CVE-2021-33175 | HIGH | 7.5 | 1.1% | Jun 8, 2021 | EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consum... |
| CVE-2021-22214 | HIGH | 8.6 | 27.8% | Jun 8, 2021 | When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE... |
| CVE-2021-22550 | HIGH | 7.8 | 0.1% | Jun 8, 2021 | An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave.... |
| CVE-2021-22549 | HIGH | 7.8 | 0.1% | Jun 8, 2021 | An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended t... |
| CVE-2021-22548 | HIGH | 7.8 | 0.1% | Jun 8, 2021 | An attacker can change the pointer to untrusted memory to point to trusted memory region which causes copying trusted me... |
| CVE-2021-22212 | HIGH | 7.4 | 0.5% | Jun 8, 2021 | ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters... |
| CVE-2021-23169 | HIGH | 8.8 | 2.3% | Jun 8, 2021 | A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker co... |
| CVE-2021-22116 | HIGH | 7.5 | 1.4% | Jun 8, 2021 | RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in... |
| CVE-2021-33560 | HIGH | 7.5 | 2.3% | Jun 8, 2021 | Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to addres... |
| CVE-2021-23392 | HIGH | 7.5 | 1.9% | Jun 8, 2021 | The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir... |
| CVE-2021-28811 | HIGH | 7.2 | 1.5% | Jun 8, 2021 | If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has... |
| CVE-2021-28810 | HIGH | 7.5 | 1.0% | Jun 8, 2021 | If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without prope... |
| CVE-2021-3277 | HIGH | 7.2 | 54.6% | Jun 7, 2021 | Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rena... |
| CVE-2021-29504 | HIGH | 7.4 | 1.3% | Jun 7, 2021 | WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI ve... |
| CVE-2021-23391 | HIGH | 7.1 | 0.4% | Jun 7, 2021 | This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary f... |
| CVE-2021-20259 | HIGH | 7.8 | 0.3% | Jun 7, 2021 | A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authent... |
| CVE-2021-30543 | HIGH | 8.8 | 0.8% | Jun 7, 2021 | Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a... |
| CVE-2021-30542 | HIGH | 8.8 | 0.8% | Jun 7, 2021 | Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a... |
| CVE-2021-30536 | HIGH | 8.1 | 1.2% | Jun 7, 2021 | Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack c... |
| CVE-2021-30535 | HIGH | 8.8 | 1.1% | Jun 7, 2021 | Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corrupti... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now