2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-40266 | MEDIUM | 6.5 | 0.8% | Aug 22, 2023 | FreeImage before 1.18.0, ReadPalette function in PluginTIFF.cpp is vulnerabile to null pointer dereference. |
| CVE-2021-40264 | MEDIUM | 6.5 | 0.6% | Aug 22, 2023 | NULL pointer dereference vulnerability in FreeImage before 1.18.0 via the FreeImage_CloneTag function inFreeImageTag.cpp... |
| CVE-2021-40262 | MEDIUM | 6.5 | 0.6% | Aug 22, 2023 | A stack exhaustion issue was discovered in FreeImage before 1.18.0 via the Validate function in PluginRAW.cpp. |
| CVE-2021-3236 | MEDIUM | 5.5 | 0.3% | Aug 11, 2023 | vim 8.2.2348 is affected by null pointer dereference, allows local attackers to cause a denial of service (DoS) via the ... |
| CVE-2021-29057 | MEDIUM | 6.5 | 0.5% | Aug 11, 2023 | An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3, allows attackers to cause a d... |
| CVE-2021-28429 | MEDIUM | 5.5 | 0.2% | Aug 11, 2023 | Integer overflow vulnerability in av_timecode_make_string in libavutil/timecode.c in FFmpeg version 4.3.2, allows local ... |
| CVE-2021-28025 | MEDIUM | 5.5 | 0.3% | Aug 11, 2023 | Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attac... |
| CVE-2021-27524 | MEDIUM | 6.1 | 0.5% | Aug 11, 2023 | Cross Site Scripting (XSS) vulnerability in margox braft-editor version 2.3.8, allows remote attackers to execute arbitr... |
| CVE-2021-25856 | MEDIUM | 4.9 | 0.5% | Aug 11, 2023 | An issue was discovered in pcmt superMicro-CMS version 3.11, allows attackers to delete files via crafted image file in ... |
| CVE-2021-25786 | MEDIUM | 5.3 | 0.5% | Aug 11, 2023 | An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file ... |
| CVE-2021-31651 | MEDIUM | 4.8 | 0.3% | Jul 31, 2023 | Cross Site Scripting (XSS) vulnerability in neofarg-cms 0.2.3 allows remoate attacker to run arbitrary code via the copy... |
| CVE-2021-4324 | MEDIUM | 6.5 | 0.5% | Jul 29, 2023 | Insufficient policy enforcement in Google Update in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to rea... |
| CVE-2021-4323 | MEDIUM | 6.5 | 0.4% | Jul 29, 2023 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who ... |
| CVE-2021-4321 | MEDIUM | 4.3 | 0.4% | Jul 29, 2023 | Policy bypass in Blink in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security polic... |
| CVE-2021-4316 | MEDIUM | 4.3 | 0.4% | Jul 29, 2023 | Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browse... |
| CVE-2021-36580 | MEDIUM | 6.1 | 1.6% | Jul 27, 2023 | Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the refere... |
| CVE-2021-39421 | MEDIUM | 6.1 | 0.4% | Jul 24, 2023 | A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML ... |
| CVE-2021-39425 | MEDIUM | 6.1 | 0.5% | Jul 20, 2023 | SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to ... |
| CVE-2021-45094 | MEDIUM | 5.4 | 0.5% | Jul 20, 2023 | Imprivata Privileged Access Management (formally Xton Privileged Access Management) 2.3.202112051108 allows XSS. |
| CVE-2021-33294 | MEDIUM | 5.5 | 0.3% | Jul 18, 2023 | In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to caus... |
| CVE-2021-32256 | MEDIUM | 6.5 | 0.7% | Jul 18, 2023 | An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_... |
| CVE-2021-43072 | MEDIUM | 6.7 | 0.2% | Jul 18, 2023 | A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and bel... |
| CVE-2021-31294 | MEDIUM | 5.9 | 1.3% | Jul 15, 2023 | Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative ... |
| CVE-2021-0948 | MEDIUM | 5.5 | 0.1% | Jul 13, 2023 | The PVRSRVBridgeGetMultiCoreInfo ioctl in the PowerVR kernel driver can return uninitialized kernel memory to user space... |
| CVE-2021-44696 | MEDIUM | 5.5 | 0.3% | Jul 12, 2023 | Adobe Prelude version 22.1.1 (and earlier) is affected by an out-of-bounds read vulnerability that could lead to disclos... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now