2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29670 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-29668 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-20371 | MEDIUM | 6.5 | 1.2% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an e... |
| CVE-2021-20348 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20347 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20346 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20345 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20343 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20338 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-3499 | MEDIUM | 5.6 | 0.8% | Jun 2, 2021 | A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not rel... |
| CVE-2021-3468 | MEDIUM | 5.5 | 0.4% | Jun 2, 2021 | A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection o... |
| CVE-2021-31855 | MEDIUM | 6.5 | 0.6% | Jun 2, 2021 | KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a de... |
| CVE-2021-28678 | MEDIUM | 5.5 | 0.7% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after ju... |
| CVE-2021-3522 | MEDIUM | 5.5 | 5.4% | Jun 2, 2021 | GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags. |
| CVE-2021-28675 | MEDIUM | 5.5 | 1.0% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input... |
| CVE-2021-3545 | MEDIUM | 6.5 | 0.4% | Jun 2, 2021 | An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versio... |
| CVE-2021-3544 | MEDIUM | 6.5 | 0.4% | Jun 2, 2021 | Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and inclu... |
| CVE-2021-23896 | MEDIUM | 4.5 | 0.2% | Jun 2, 2021 | Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security... |
| CVE-2021-29091 | MEDIUM | 6.5 | 1.1% | Jun 2, 2021 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management componen... |
| CVE-2021-32657 | MEDIUM | 4.3 | 1.8% | Jun 1, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions of Nextcloud Server prior to 10.0.11, 20.... |
| CVE-2021-3425 | MEDIUM | 4.4 | 0.3% | Jun 1, 2021 | A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker... |
| CVE-2021-26111 | MEDIUM | 6.5 | 0.4% | Jun 1, 2021 | A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 ... |
| CVE-2021-3424 | MEDIUM | 5.3 | 0.8% | Jun 1, 2021 | A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malici... |
| CVE-2021-32652 | MEDIUM | 4.3 | 1.1% | Jun 1, 2021 | Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1... |
| CVE-2021-32651 | MEDIUM | 4.3 | 1.1% | Jun 1, 2021 | OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now