2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3798 | MEDIUM | 5.5 | 0.3% | Aug 23, 2022 | A flaw was found in openCryptoki. The openCryptoki Soft token does not check if an EC key is valid when an EC key is cre... |
| CVE-2021-3764 | MEDIUM | 5.5 | 0.3% | Aug 23, 2022 | A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a den... |
| CVE-2021-3763 | MEDIUM | 4.3 | 0.6% | Aug 23, 2022 | A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access so... |
| CVE-2021-3759 | MEDIUM | 5.5 | 0.3% | Aug 23, 2022 | A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a u... |
| CVE-2021-3736 | MEDIUM | 5.5 | 0.2% | Aug 23, 2022 | A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in V... |
| CVE-2021-3714 | MEDIUM | 5.9 | 1.1% | Aug 23, 2022 | A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication ... |
| CVE-2021-3702 | MEDIUM | 6.3 | 0.2% | Aug 23, 2022 | A race condition flaw was found in ansible-runner, where an attacker could watch for rapid creation and deletion of a te... |
| CVE-2021-3701 | MEDIUM | 6.6 | 0.3% | Aug 23, 2022 | A flaw was found in ansible-runner where the default temporary files configuration in ansible-2.0.0 are written to world... |
| CVE-2021-3670 | MEDIUM | 6.5 | 1.7% | Aug 23, 2022 | MaxQueryDuration not honoured in Samba AD DC LDAP |
| CVE-2021-20316 | MEDIUM | 6.8 | 0.8% | Aug 23, 2022 | A flaw was found in the way Samba handled file/directory metadata. This flaw allows an authenticated attacker with permi... |
| CVE-2021-29891 | MEDIUM | 4.9 | 0.4% | Aug 22, 2022 | IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause... |
| CVE-2021-3659 | MEDIUM | 5.5 | 0.3% | Aug 22, 2022 | A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way t... |
| CVE-2021-3639 | MEDIUM | 6.1 | 0.8% | Aug 22, 2022 | A flaw was found in mod_auth_mellon where it does not sanitize logout URLs properly. This issue could be used by an atta... |
| CVE-2021-3521 | MEDIUM | 4.7 | 0.3% | Aug 22, 2022 | There is a flaw in RPM's signature functionality. OpenPGP subkeys are associated with a primary key via a "binding signa... |
| CVE-2021-3442 | MEDIUM | 5.4 | 0.4% | Aug 22, 2022 | A flaw was found in the Red Hat OpenShift API Management product. User input is not validated allowing an authenticated ... |
| CVE-2021-36857 | MEDIUM | 5.4 | 0.5% | Aug 22, 2022 | Authenticated (editor+) Stored Cross-Site Scripting (XSS) vulnerability in wpshopmart Testimonial Builder plugin <= 1.6.... |
| CVE-2021-36847 | MEDIUM | 4.8 | 0.5% | Aug 22, 2022 | Authenticated (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WebbaPlugins Webba Booking plugin <= 4.2.21 at... |
| CVE-2021-24912 | MEDIUM | 5.4 | 0.3% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not have CSRF check in its tp_translation AJAX ac... |
| CVE-2021-24911 | MEDIUM | 5.4 | 0.6% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the tk0 parameter from th... |
| CVE-2021-24910 | MEDIUM | 6.1 | 1.3% | Aug 22, 2022 | The Transposh WordPress Translation WordPress plugin before 1.0.8 does not sanitise and escape the a parameter via an AJ... |
| CVE-2021-44545 | MEDIUM | 6.5 | 0.5% | Aug 18, 2022 | Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticat... |
| CVE-2021-44470 | MEDIUM | 5.5 | 0.2% | Aug 18, 2022 | Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authentic... |
| CVE-2021-33128 | MEDIUM | 4.4 | 0.2% | Aug 18, 2022 | Improper access control in the firmware for some Intel(R) E810 Ethernet Controllers before version 1.6.0.6 may allow a p... |
| CVE-2021-33126 | MEDIUM | 4.4 | 0.2% | Aug 18, 2022 | Improper access control in the firmware for some Intel(R) 700 and 722 Series Ethernet Controllers and Adapters before ve... |
| CVE-2021-26950 | MEDIUM | 5.5 | 0.2% | Aug 18, 2022 | Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before versi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now