2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3020 | HIGH | 8.8 | 1.0% | Aug 26, 2022 | An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (buil... |
| CVE-2021-4112 | HIGH | 8.8 | 0.2% | Aug 25, 2022 | A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows... |
| CVE-2021-3929 | HIGH | 8.2 | 0.6% | Aug 25, 2022 | A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021... |
| CVE-2021-43766 | HIGH | 8.1 | 0.5% | Aug 25, 2022 | Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common N... |
| CVE-2021-42523 | HIGH | 7.5 | 0.8% | Aug 25, 2022 | There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src... |
| CVE-2021-42522 | HIGH | 7.5 | 0.7% | Aug 25, 2022 | There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was ca... |
| CVE-2021-42521 | HIGH | 7.5 | 1.1% | Aug 25, 2022 | There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. T... |
| CVE-2021-25642 | HIGH | 8.8 | 1.8% | Aug 25, 2022 | ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from... |
| CVE-2021-4213 | HIGH | 7.5 | 1.2% | Aug 24, 2022 | A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the ser... |
| CVE-2021-4204 | HIGH | 7.1 | 1.1% | Aug 24, 2022 | An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This... |
| CVE-2021-4125 | HIGH | 8.1 | 1.2% | Aug 24, 2022 | It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers... |
| CVE-2021-4041 | HIGH | 7.8 | 0.3% | Aug 24, 2022 | A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interfac... |
| CVE-2021-4028 | HIGH | 7.8 | 0.3% | Aug 24, 2022 | A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local ... |
| CVE-2021-43309 | HIGH | 7.5 | 0.9% | Aug 24, 2022 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when ... |
| CVE-2021-3999 | HIGH | 7.8 | 0.7% | Aug 24, 2022 | A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when th... |
| CVE-2021-3998 | HIGH | 7.5 | 1.4% | Aug 24, 2022 | A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to inf... |
| CVE-2021-0947 | HIGH | 7.5 | 0.3% | Aug 24, 2022 | The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLSer... |
| CVE-2021-0946 | HIGH | 7.5 | 0.3% | Aug 24, 2022 | The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer v... |
| CVE-2021-0891 | HIGH | 7.5 | 0.3% | Aug 24, 2022 | An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Pro... |
| CVE-2021-3905 | HIGH | 7.5 | 1.6% | Aug 23, 2022 | A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this f... |
| CVE-2021-3839 | HIGH | 7.5 | 1.3% | Aug 23, 2022 | A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inf... |
| CVE-2021-3690 | HIGH | 7.5 | 1.4% | Aug 23, 2022 | A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This f... |
| CVE-2021-31566 | HIGH | 7.8 | 0.4% | Aug 23, 2022 | An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control ... |
| CVE-2021-23177 | HIGH | 7.8 | 0.4% | Aug 23, 2022 | An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the t... |
| CVE-2021-20304 | HIGH | 7.5 | 1.5% | Aug 23, 2022 | A flaw was found in OpenEXR's hufDecode functionality. This flaw allows an attacker who can pass a crafted file to be pr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now