2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31555 | HIGH | 7.5 | 0.8% | Apr 22, 2021 | An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. It did not validate the oarc_version (aka o... |
| CVE-2021-29466 | HIGH | 7.5 | 1.6% | Apr 22, 2021 | Discord-Recon is a bot for the Discord chat service. In versions of Discord-Recon 0.0.3 and prior, a remote attacker is ... |
| CVE-2021-1076 | HIGH | 7.8 | 0.3% | Apr 21, 2021 | NVIDIA GPU Display Driver for Windows and Linux, all versions, contains a vulnerability in the kernel mode layer (nvlddm... |
| CVE-2021-1075 | HIGH | 7.3 | 0.2% | Apr 21, 2021 | NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm... |
| CVE-2021-1074 | HIGH | 7.3 | 0.5% | Apr 21, 2021 | NVIDIA GPU Display Driver for Windows installer contains a vulnerability where an attacker with local unprivileged syste... |
| CVE-2021-21427 | HIGH | 7.2 | 1.1% | Apr 21, 2021 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). A vulnerability in magento-lts version... |
| CVE-2021-31523 | HIGH | 7.8 | 0.3% | Apr 21, 2021 | The Debian xscreensaver 5.42+dfsg1-1 package for XScreenSaver has cap_net_raw enabled for the /usr/libexec/xscreensaver/... |
| CVE-2021-30139 | HIGH | 7.5 | 1.6% | Apr 21, 2021 | In Alpine Linux apk-tools before 2.12.5, the tarball parser allows a buffer overflow and crash. |
| CVE-2021-21646 | HIGH | 8.8 | 1.7% | Apr 21, 2021 | Jenkins Templating Engine Plugin 2.1 and earlier does not protect its pipeline configurations using Script Security Plug... |
| CVE-2021-21642 | HIGH | 8.1 | 37.8% | Apr 21, 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (... |
| CVE-2021-20501 | HIGH | 8.2 | 1.3% | Apr 21, 2021 | IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to th... |
| CVE-2021-20454 | HIGH | 8.2 | 2.9% | Apr 21, 2021 | IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack wh... |
| CVE-2021-28965 | HIGH | 7.5 | 5.1% | Apr 21, 2021 | The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML ... |
| CVE-2021-29461 | HIGH | 8.8 | 2.5% | Apr 20, 2021 | Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in ... |
| CVE-2021-30464 | HIGH | 7.5 | 1.2% | Apr 20, 2021 | OMICRON StationGuard before 1.10 allows remote attackers to cause a denial of service (connectivity outage) via crafted ... |
| CVE-2021-28829 | HIGH | 8 | 0.7% | Apr 20, 2021 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ... |
| CVE-2021-28828 | HIGH | 8.8 | 0.8% | Apr 20, 2021 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator ... |
| CVE-2021-28156 | HIGH | 7.5 | 2.3% | Apr 20, 2021 | HashiCorp Consul Enterprise version 1.8.0 up to 1.9.4 audit log can be bypassed by specifically crafted HTTP events. Fix... |
| CVE-2021-25681 | HIGH | 7.5 | 13.4% | Apr 20, 2021 | AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. T... |
| CVE-2021-20453 | HIGH | 8.2 | 2.6% | Apr 20, 2021 | IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when pr... |
| CVE-2021-3035 | HIGH | 7.2 | 1.3% | Apr 20, 2021 | An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when proce... |
| CVE-2021-3506 | HIGH | 7.1 | 0.4% | Apr 19, 2021 | An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions... |
| CVE-2021-27458 | HIGH | 7.5 | 1.1% | Apr 19, 2021 | If Ethernet communication of the JTEKT Corporation TOYOPUC product series’ (TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All... |
| CVE-2021-3498 | HIGH | 7.8 | 1.8% | Apr 19, 2021 | GStreamer before 1.18.4 might cause heap corruption when parsing certain malformed Matroska files. |
| CVE-2021-3497 | HIGH | 7.8 | 1.2% | Apr 19, 2021 | GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska f... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now