2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29823MEDIUM6.5IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacke...
CVE-2021-20468MEDIUM6.5IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to cross-site request forgery which could allow an attacke...
CVE-2021-29864MEDIUM6.1IBM Security Identity Manager 6.0 and 6.0.2 could allow a remote attacker to conduct phishing attacks, using an open red...
CVE-2021-46837MEDIUM6.5res_pjsip_t38 in Sangoma Asterisk 16.x before 16.16.2, 17.x before 17.9.3, and 18.x before 18.2.2, and Certified Asteris...
CVE-2021-38934MEDIUM5.4IBM Engineering Test Management 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2021-40326MEDIUM5.5Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, mishandle hidden and incremental ...
CVE-2021-4216MEDIUM5.5A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in...
CVE-2021-3856MEDIUM4.3ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classl...
CVE-2021-3754MEDIUM5.3A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any...
CVE-2021-3735MEDIUM4.4A deadlock issue was found in the AHCI controller device of QEMU. It occurs on a software reset (ahci_reset_port) while ...
CVE-2021-3688MEDIUM4.8A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the pa...
CVE-2021-3669MEDIUM5.5A flaw was found in the Linux kernel. Measuring usage of the shared memory does not scale with large shared memory segme...
CVE-2021-3585MEDIUM5.5A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deploymen...
CVE-2021-3427MEDIUM6.1The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly s...
CVE-2021-35939MEDIUM6.7It was found that the fix for CVE-2017-7500 and CVE-2017-7501 was incomplete: the check was only implemented for the par...
CVE-2021-39394MEDIUM6.5mm-wiki v0.2.1 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add u...
CVE-2021-39393MEDIUM6.1mm-wiki v0.2.1 was discovered to contain a cross-site scripting (XSS) vulnerability via the markdown editor.
CVE-2021-32570MEDIUM4.9In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retriev...
CVE-2021-3979MEDIUM6.5A key length flaw was found in Red Hat Ceph Storage. An attacker can exploit the fact that the key length is incorrectly...
CVE-2021-3914MEDIUM6.1It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could...
CVE-2021-35938MEDIUM6.7A symbolic link issue was found in rpm. It occurs when rpm sets the desired permissions and credentials after installing...
CVE-2021-35937MEDIUM6.4A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that...
CVE-2021-33844MEDIUM5.5A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacke...
CVE-2021-23210MEDIUM5.5A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An atta...
CVE-2021-23172MEDIUM5.5A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulner...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now