2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21173 | MEDIUM | 6.5 | 1.6% | Mar 9, 2021 | Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker t... |
| CVE-2021-21171 | MEDIUM | 6.5 | 1.7% | Mar 9, 2021 | Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 allowed a remote atta... |
| CVE-2021-21170 | MEDIUM | 6.5 | 1.6% | Mar 9, 2021 | Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the... |
| CVE-2021-21168 | MEDIUM | 6.5 | 1.8% | Mar 9, 2021 | Insufficient policy enforcement in appcache in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain p... |
| CVE-2021-21164 | MEDIUM | 6.5 | 0.8% | Mar 9, 2021 | Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to... |
| CVE-2021-21163 | MEDIUM | 6.5 | 0.9% | Mar 9, 2021 | Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to l... |
| CVE-2021-20262 | MEDIUM | 6.8 | 0.3% | Mar 9, 2021 | A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows... |
| CVE-2021-20253 | MEDIUM | 6.7 | 0.4% | Mar 9, 2021 | A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker t... |
| CVE-2021-20243 | MEDIUM | 5.5 | 1.1% | Mar 9, 2021 | A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by Imag... |
| CVE-2021-20241 | MEDIUM | 5.5 | 1.1% | Mar 9, 2021 | A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick... |
| CVE-2021-3417 | MEDIUM | 4.9 | 0.5% | Mar 9, 2021 | An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Admi... |
| CVE-2021-21488 | MEDIUM | 6.5 | 1.3% | Mar 9, 2021 | Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deser... |
| CVE-2021-20341 | MEDIUM | 5.3 | 1.0% | Mar 9, 2021 | IBM Cloud Pak for Multicloud Management Monitoring 2.2 returns potentially sensitive information in headers which could ... |
| CVE-2021-28006 | MEDIUM | 6.1 | 0.9% | Mar 9, 2021 | Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter. |
| CVE-2021-24033 | MEDIUM | 5.6 | 3.3% | Mar 9, 2021 | react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a c... |
| CVE-2021-21361 | MEDIUM | 6.5 | 1.2% | Mar 9, 2021 | The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the loggi... |
| CVE-2021-21360 | MEDIUM | 5.3 | 1.5% | Mar 9, 2021 | Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem arti... |
| CVE-2021-21510 | MEDIUM | 6.1 | 1.0% | Mar 8, 2021 | Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attack... |
| CVE-2021-22134 | MEDIUM | 4.3 | 1.1% | Mar 8, 2021 | A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Leve... |
| CVE-2021-21337 | MEDIUM | 6.1 | 8.4% | Mar 8, 2021 | Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS... |
| CVE-2021-21336 | MEDIUM | 6.5 | 1.5% | Mar 8, 2021 | Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS... |
| CVE-2021-21362 | MEDIUM | 6.5 | 1.3% | Mar 8, 2021 | MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage se... |
| CVE-2021-21354 | MEDIUM | 6.1 | 1.4% | Mar 8, 2021 | Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things... |
| CVE-2021-21326 | MEDIUM | 6.5 | 1.4% | Mar 8, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2021-21325 | MEDIUM | 4.8 | 0.6% | Mar 8, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now