2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2021-3020HIGH8.8An issue was discovered in ClusterLabs Hawk (aka HA Web Konsole) through 2.3.0-15. It ships the binary hawk_invoke (buil...
CVE-2021-4112HIGH8.8A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows...
CVE-2021-3929HIGH8.2A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021...
CVE-2021-43766HIGH8.1Odyssey passes to server unencrypted bytes from man-in-the-middle When Odyssey is configured to use certificate Common N...
CVE-2021-42523HIGH7.5There are two Information Disclosure vulnerabilities in colord, and they lie in colord/src/cd-device-db.c and colord/src...
CVE-2021-42522HIGH7.5There is a Information Disclosure vulnerability in anjuta/plugins/document-manager/anjuta-bookmarks.c. This issue was ca...
CVE-2021-42521HIGH7.5There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. T...
CVE-2021-25642HIGH8.8ZKConfigurationStore which is optionally used by CapacityScheduler of Apache Hadoop YARN deserializes data obtained from...
CVE-2021-4213HIGH7.5A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the ser...
CVE-2021-4204HIGH7.1An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This...
CVE-2021-4125HIGH8.1It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers...
CVE-2021-4041HIGH7.8A flaw was found in ansible-runner. An improper escaping of the shell command, while calling the ansible_runner.interfac...
CVE-2021-4028HIGH7.8A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local ...
CVE-2021-43309HIGH7.5An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when ...
CVE-2021-3999HIGH7.8A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when th...
CVE-2021-3998HIGH7.5A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to inf...
CVE-2021-0947HIGH7.5The method PVRSRVBridgeTLDiscoverStreams allocates puiStreamsInt on the heap, fills the contents of the buffer via TLSer...
CVE-2021-0946HIGH7.5The method PVRSRVBridgePMRPDumpSymbolicAddr allocates puiMemspaceNameInt on the heap, fills the contents of the buffer v...
CVE-2021-0891HIGH7.5An unprivileged app can trigger PowerVR driver to return an uninitialized heap memory causing information disclosure.Pro...
CVE-2021-3905HIGH7.5A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this f...
CVE-2021-3839HIGH7.5A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inf...
CVE-2021-3690HIGH7.5A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This f...
CVE-2021-31566HIGH7.8An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control ...
CVE-2021-23177HIGH7.8An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the t...
CVE-2021-20304HIGH7.5A flaw was found in OpenEXR's hufDecode functionality. This flaw allows an attacker who can pass a crafted file to be pr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now