2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31525 | MEDIUM | 5.9 | 3.7% | May 27, 2021 | net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via ... |
| CVE-2021-22411 | MEDIUM | 6.5 | 0.6% | May 27, 2021 | There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. A... |
| CVE-2021-22364 | MEDIUM | 5.5 | 0.2% | May 27, 2021 | There is a denial of service vulnerability in the versions 10.1.0.126(C00E125R5P3) of HUAWEI Mate 30 and 10.1.0.152(C00E... |
| CVE-2021-22362 | MEDIUM | 5.3 | 0.7% | May 27, 2021 | There is an out of bounds write vulnerability in some Huawei products. An attacker can exploit this vulnerability by sen... |
| CVE-2021-22360 | MEDIUM | 4.9 | 0.6% | May 27, 2021 | There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC... |
| CVE-2021-22358 | MEDIUM | 4.3 | 0.5% | May 27, 2021 | There is an insufficient input validation vulnerability in FusionCompute 8.0.0. Due to the input validation is insuffici... |
| CVE-2021-28662 | MEDIUM | 6.5 | 71.9% | May 27, 2021 | An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response heade... |
| CVE-2021-28652 | MEDIUM | 4.9 | 4.3% | May 27, 2021 | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denia... |
| CVE-2021-32459 | MEDIUM | 6.5 | 1.0% | May 27, 2021 | Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log co... |
| CVE-2021-20727 | MEDIUM | 6.1 | 1.0% | May 27, 2021 | Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by l... |
| CVE-2021-33586 | MEDIUM | 4.3 | 0.9% | May 27, 2021 | InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocate... |
| CVE-2021-31920 | MEDIUM | 6.5 | 1.2% | May 27, 2021 | Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multi... |
| CVE-2021-3509 | MEDIUM | 6.1 | 1.7% | May 27, 2021 | A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was... |
| CVE-2021-30501 | MEDIUM | 5.5 | 1.0% | May 27, 2021 | An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to ca... |
| CVE-2021-3527 | MEDIUM | 5.5 | 0.4% | May 26, 2021 | A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large t... |
| CVE-2021-3486 | MEDIUM | 6.1 | 1.4% | May 26, 2021 | GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code. |
| CVE-2021-30471 | MEDIUM | 5.5 | 0.7% | May 26, 2021 | A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo... |
| CVE-2021-30470 | MEDIUM | 5.5 | 0.7% | May 26, 2021 | A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextV... |
| CVE-2021-30469 | MEDIUM | 5.5 | 0.7% | May 26, 2021 | A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of ser... |
| CVE-2021-28170 | MEDIUM | 5.3 | 2.1% | May 26, 2021 | In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid E... |
| CVE-2021-20196 | MEDIUM | 6.5 | 0.5% | May 26, 2021 | A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/w... |
| CVE-2021-25643 | MEDIUM | 4.9 | 0.5% | May 26, 2021 | An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with adminis... |
| CVE-2021-20297 | MEDIUM | 5.5 | 0.3% | May 26, 2021 | A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes Networ... |
| CVE-2021-20191 | MEDIUM | 5.5 | 0.3% | May 26, 2021 | A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protect... |
| CVE-2021-20177 | MEDIUM | 4.4 | 0.3% | May 26, 2021 | A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root o... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now