2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31702 | HIGH | 7.5 | 1.2% | May 29, 2021 | Frontier ichris through 5.18 mishandles making a DNS request for the hostname in the HTTP Host header, as demonstrated b... |
| CVE-2021-32621 | HIGH | 8.8 | 2.1% | May 28, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions pri... |
| CVE-2021-32620 | HIGH | 8.8 | 1.1% | May 28, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions pri... |
| CVE-2021-29505 | HIGH | 8.8 | 77.7% | May 28, 2021 | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4... |
| CVE-2021-29492 | HIGH | 8.3 | 68.4% | May 28, 2021 | Envoy is a cloud-native edge/middle/service proxy. Envoy does not decode escaped slash sequences `%2F` and `%5C` in HTTP... |
| CVE-2021-33587 | HIGH | 7.5 | 2.3% | May 28, 2021 | The css-what package 4.0.0 through 5.0.0 for Node.js does not ensure that attribute parsing has Linear Time Complexity r... |
| CVE-2021-20267 | HIGH | 7.1 | 1.0% | May 28, 2021 | A flaw was found in openstack-neutron's default Open vSwitch firewall rules. By sending carefully crafted packets, anyon... |
| CVE-2021-33623 | HIGH | 7.5 | 2.8% | May 28, 2021 | The trim-newlines package before 3.0.1 and 4.x before 4.0.1 for Node.js has an issue related to regular expression denia... |
| CVE-2021-32646 | HIGH | 7.3 | 0.7% | May 28, 2021 | Roomer is a discord bot cog (extension) which provides automatic voice channel generation as well as private voice and t... |
| CVE-2021-29629 | HIGH | 7.5 | 1.2% | May 28, 2021 | In FreeBSD 13.0-STABLE before n245765-bec0d2c9c841, 12.2-STABLE before r369859, 11.4-STABLE before r369866, 13.0-RELEASE... |
| CVE-2021-29628 | HIGH | 7.5 | 1.2% | May 28, 2021 | In FreeBSD 13.0-STABLE before n245764-876ffe28796c, 12.2-STABLE before r369857, 13.0-RELEASE before p1, and 12.2-RELEASE... |
| CVE-2021-27032 | HIGH | 7.8 | 0.2% | May 28, 2021 | Autodesk Licensing Installer was found to be vulnerable to privilege escalation issues. A malicious user with limited pr... |
| CVE-2021-33591 | HIGH | 8.8 | 1.6% | May 28, 2021 | An exposed remote debugging port in Naver Comic Viewer prior to 1.0.15.0 allowed a remote attacker to execute arbitrary ... |
| CVE-2021-20240 | HIGH | 8.8 | 2.3% | May 28, 2021 | A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can oc... |
| CVE-2021-20237 | HIGH | 7.5 | 1.7% | May 28, 2021 | An uncontrolled resource consumption (memory leak) flaw was found in ZeroMQ's src/xpub.cpp in versions before 4.3.3. Thi... |
| CVE-2021-20026 | HIGH | 8.8 | 11.6% | May 27, 2021 | A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection us... |
| CVE-2021-27490 | HIGH | 7.8 | 2.0% | May 27, 2021 | Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versi... |
| CVE-2021-27496 | HIGH | 7.8 | 2.0% | May 27, 2021 | Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versi... |
| CVE-2021-27494 | HIGH | 7.8 | 2.2% | May 27, 2021 | Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versi... |
| CVE-2021-27488 | HIGH | 7.8 | 2.0% | May 27, 2021 | Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versi... |
| CVE-2021-22118 | HIGH | 7.8 | 0.4% | May 27, 2021 | In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerab... |
| CVE-2021-33200 | HIGH | 7.8 | 0.4% | May 27, 2021 | kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, ak... |
| CVE-2021-31155 | HIGH | 7.8 | 0.4% | May 27, 2021 | Failure to normalize the umask in please before 0.4 allows a local attacker to gain full root privileges if they are all... |
| CVE-2021-31154 | HIGH | 7.8 | 0.5% | May 27, 2021 | pleaseedit in please before 0.4 uses predictable temporary filenames in /tmp and the target directory. This allows a loc... |
| CVE-2021-30465 | HIGH | 8.5 | 6.6% | May 27, 2021 | runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now