2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29670MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-29668MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-20371MEDIUM6.5IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an e...
CVE-2021-20348MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20347MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20346MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20345MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20343MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20338MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-3499MEDIUM5.6A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not rel...
CVE-2021-3468MEDIUM5.5A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection o...
CVE-2021-31855MEDIUM6.5KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a de...
CVE-2021-28678MEDIUM5.5An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after ju...
CVE-2021-3522MEDIUM5.5GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
CVE-2021-28675MEDIUM5.5An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input...
CVE-2021-3545MEDIUM6.5An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versio...
CVE-2021-3544MEDIUM6.5Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and inclu...
CVE-2021-23896MEDIUM4.5Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security...
CVE-2021-29091MEDIUM6.5Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management componen...
CVE-2021-32657MEDIUM4.3Nextcloud Server is a Nextcloud package that handles data storage. In versions of Nextcloud Server prior to 10.0.11, 20....
CVE-2021-3425MEDIUM4.4A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker...
CVE-2021-26111MEDIUM6.5A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 ...
CVE-2021-3424MEDIUM5.3A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malici...
CVE-2021-32652MEDIUM4.3Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1...
CVE-2021-32651MEDIUM4.3OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now