2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-31525MEDIUM5.9net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via ...
CVE-2021-22411MEDIUM6.5There is an out-of-bounds write vulnerability in some Huawei products. The code of a module have a bad judgment logic. A...
CVE-2021-22364MEDIUM5.5There is a denial of service vulnerability in the versions 10.1.0.126(C00E125R5P3) of HUAWEI Mate 30 and 10.1.0.152(C00E...
CVE-2021-22362MEDIUM5.3There is an out of bounds write vulnerability in some Huawei products. An attacker can exploit this vulnerability by sen...
CVE-2021-22360MEDIUM4.9There is a resource management error vulnerability in the verisions V500R001C60SPC500, V500R005C00SPC100, V500R005C00SPC...
CVE-2021-22358MEDIUM4.3There is an insufficient input validation vulnerability in FusionCompute 8.0.0. Due to the input validation is insuffici...
CVE-2021-28662MEDIUM6.5An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response heade...
CVE-2021-28652MEDIUM4.9An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denia...
CVE-2021-32459MEDIUM6.5Trend Micro Home Network Security version 6.6.604 and earlier contains a hard-coded password vulnerability in the log co...
CVE-2021-20727MEDIUM6.1Cross-site scripting vulnerability in Zettlr from 0.20.0 to 1.8.8 allows an attacker to execute an arbitrary script by l...
CVE-2021-33586MEDIUM4.3InspIRCd 3.8.0 through 3.9.x before 3.10.0 allows any user (able to connect to the server) to access recently deallocate...
CVE-2021-31920MEDIUM6.5Istio before 1.8.6 and 1.9.x before 1.9.5 has a remotely exploitable vulnerability where an HTTP request path with multi...
CVE-2021-3509MEDIUM6.1A flaw was found in Red Hat Ceph Storage 4, in the Dashboard component. In response to CVE-2020-27839, the JWT token was...
CVE-2021-30501MEDIUM5.5An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to ca...
CVE-2021-3527MEDIUM5.5A flaw was found in the USB redirector device (usb-redir) of QEMU. Small USB packets are combined into a single, large t...
CVE-2021-3486MEDIUM6.1GLPi 9.5.4 does not sanitize the metadata. This way its possible to insert XSS into plugins to execute JavaScript code.
CVE-2021-30471MEDIUM5.5A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo...
CVE-2021-30470MEDIUM5.5A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextV...
CVE-2021-30469MEDIUM5.5A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of ser...
CVE-2021-28170MEDIUM5.3In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid E...
CVE-2021-20196MEDIUM6.5A NULL pointer dereference flaw was found in the floppy disk emulator of QEMU. This issue occurs while processing read/w...
CVE-2021-25643MEDIUM4.9An issue was discovered in Couchbase Server 5.x and 6.x before 6.5.2 and 6.6.x before 6.6.2. Internal users with adminis...
CVE-2021-20297MEDIUM5.5A flaw was found in NetworkManager in versions before 1.30.0. Setting match.path and activating a profile crashes Networ...
CVE-2021-20191MEDIUM5.5A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protect...
CVE-2021-20177MEDIUM4.4A flaw was found in the Linux kernel's implementation of string matching within a packet. A privileged user (with root o...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now