2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29554 | MEDIUM | 5.5 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a F... |
| CVE-2021-20565 | MEDIUM | 5.3 | 0.8% | May 14, 2021 | IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 uses a protection mechanism that relie... |
| CVE-2021-20564 | MEDIUM | 5.9 | 0.9% | May 14, 2021 | IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtai... |
| CVE-2021-20429 | MEDIUM | 5.3 | 0.8% | May 14, 2021 | IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cro... |
| CVE-2021-20392 | MEDIUM | 6.1 | 0.7% | May 14, 2021 | IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2021-32613 | MEDIUM | 5.5 | 1.2% | May 14, 2021 | In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS. |
| CVE-2021-24291 | MEDIUM | 6.1 | 14.4% | May 14, 2021 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cr... |
| CVE-2021-24287 | MEDIUM | 6.1 | 10.4% | May 14, 2021 | The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before ... |
| CVE-2021-24286 | MEDIUM | 6.1 | 13.9% | May 14, 2021 | The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab paramete... |
| CVE-2021-24283 | MEDIUM | 5.4 | 0.6% | May 14, 2021 | The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, lead... |
| CVE-2021-24282 | MEDIUM | 6.3 | 0.7% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could... |
| CVE-2021-24281 | MEDIUM | 4.3 | 0.7% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could... |
| CVE-2021-24279 | MEDIUM | 6.5 | 0.8% | May 14, 2021 | In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the... |
| CVE-2021-24277 | MEDIUM | 5.4 | 0.6% | May 14, 2021 | The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settin... |
| CVE-2021-31876 | MEDIUM | 6.5 | 1.6% | May 13, 2021 | Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes i... |
| CVE-2021-29506 | MEDIUM | 6.5 | 1.4% | May 13, 2021 | GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a re... |
| CVE-2021-23906 | MEDIUM | 6.8 | 0.8% | May 13, 2021 | An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A M... |
| CVE-2021-32925 | MEDIUM | 6.5 | 1.9% | May 13, 2021 | admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities. |
| CVE-2021-22139 | MEDIUM | 6.5 | 1.0% | May 13, 2021 | Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack o... |
| CVE-2021-22137 | MEDIUM | 5.3 | 1.1% | May 13, 2021 | In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Sec... |
| CVE-2021-22135 | MEDIUM | 5.3 | 1.2% | May 13, 2021 | Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch sugges... |
| CVE-2021-32921 | MEDIUM | 5.9 | 1.6% | May 13, 2021 | An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret... |
| CVE-2021-32917 | MEDIUM | 5.3 | 2.2% | May 13, 2021 | An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither o... |
| CVE-2021-21424 | MEDIUM | 5.3 | 1.7% | May 13, 2021 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumera... |
| CVE-2021-20535 | MEDIUM | 5.4 | 0.5% | May 13, 2021 | IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now