2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-40266MEDIUM6.5FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference.
CVE-2021-40264MEDIUM6.5NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp...
CVE-2021-40262MEDIUM6.5A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp.
CVE-2021-3236MEDIUM5.5vim 8.2.2348 is affected by null pointer dereference, allows local attackers to cause a denial of service (DoS) via the ...
CVE-2021-29057MEDIUM6.5An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a d...
CVE-2021-28429MEDIUM5.5Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local ...
CVE-2021-28025MEDIUM5.5Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attac...
CVE-2021-27524MEDIUM6.1Cross Site Scripting (XSS) vulnerability in margox braft-editor version 2.3.8, allows remote attackers to execute arbitr...
CVE-2021-25856MEDIUM4.9An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in ...
CVE-2021-25786MEDIUM5.3An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file ...
CVE-2021-31651MEDIUM4.8Cross Site Scripting (XSS) vulnerability in neofarg-cms 0.2.3 allows remoate attacker to run arbitrary code via the copy...
CVE-2021-4324MEDIUM6.5Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to rea...
CVE-2021-4323MEDIUM6.5Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who ...
CVE-2021-4321MEDIUM4.3Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security polic...
CVE-2021-4316MEDIUM4.3Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browse...
CVE-2021-36580MEDIUM6.1Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the refere...
CVE-2021-39421MEDIUM6.1A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2021-39425MEDIUM6.1SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to ...
CVE-2021-45094MEDIUM5.4Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS.
CVE-2021-33294MEDIUM5.5In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to caus...
CVE-2021-32256MEDIUM6.5An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_...
CVE-2021-43072MEDIUM6.7A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and bel...
CVE-2021-31294MEDIUM5.9Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative ...
CVE-2021-0948MEDIUM5.5The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space...
CVE-2021-44696MEDIUM5.5Adobe Prelude version 22.1.1 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclos...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now