2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-3798MEDIUM5.5A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is cre...
CVE-2021-3764MEDIUM5.5A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a den...
CVE-2021-3763MEDIUM4.3A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access so...
CVE-2021-3759MEDIUM5.5A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a u...
CVE-2021-3736MEDIUM5.5A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in V...
CVE-2021-3714MEDIUM5.9A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication ...
CVE-2021-3702MEDIUM6.3A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a te...
CVE-2021-3701MEDIUM6.6A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world...
CVE-2021-3670MEDIUM6.5MaxQueryDuration not honoured in Samba AD DC LDAP
CVE-2021-20316MEDIUM6.8A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permi...
CVE-2021-29891MEDIUM4.9IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause...
CVE-2021-3659MEDIUM5.5A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way t...
CVE-2021-3639MEDIUM6.1A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an atta...
CVE-2021-3521MEDIUM4.7There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signa...
CVE-2021-3442MEDIUM5.4A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated ...
CVE-2021-36857MEDIUM5.4Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in wpshopmart Testimonial Builder plugin <= 1.6....
CVE-2021-36847MEDIUM4.8Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebbaPlugins Webba Booking plugin <= 4.2.21 at...
CVE-2021-24912MEDIUM5.4The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX ac...
CVE-2021-24911MEDIUM5.4The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from th...
CVE-2021-24910MEDIUM6.1The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJ...
CVE-2021-44545MEDIUM6.5Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticat...
CVE-2021-44470MEDIUM5.5Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authentic...
CVE-2021-33128MEDIUM4.4Improper access control in the firmware for some Intel(R) E810 Ethernet Controllers before version 1.6.0.6 may allow a p...
CVE-2021-33126MEDIUM4.4Improper access control in the firmware for some Intel(R) 700 and 722 Series Ethernet Controllers and Adapters before ve...
CVE-2021-26950MEDIUM5.5Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before versi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now