2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-28697HIGH7.8grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pa...
CVE-2021-28696MEDIUM6.8IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/...
CVE-2021-28695MEDIUM6.8IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/...
CVE-2021-28694MEDIUM6.8IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/...
CVE-2021-28233HIGH8.8Heap-based Buffer Overflow vulnerability exists in ok-file-formats 1 via the ok_jpg_generate_huffman_table function in o...
CVE-2021-32758HIGH7.2OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layou...
CVE-2021-23434HIGH8.6This affects the package object-path before 0.11.6. A type confusion vulnerability can lead to a bypass of CVE-2020-1525...
CVE-2021-36531HIGH8.8ngiflib 0.4 has a heap overflow in GetByte() at ngiflib.c:70 in NGIFLIB_NO_FILE mode, GetByte() reads memory buffer with...
CVE-2021-36530HIGH8.8ngiflib 0.4 has a heap overflow in GetByteStr() at ngiflib.c:108 in NGIFLIB_NO_FILE mode, GetByteStr() copy memory buffe...
CVE-2021-29744MEDIUM5.4IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2021-40153HIGH8.1squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by ...
CVE-2021-39169MEDIUM5.4Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the...
CVE-2021-35342HIGH7.5The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender E...
CVE-2021-40142HIGH7.5In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS)...
CVE-2021-39168CRITICAL9.8OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allo...
CVE-2021-39167CRITICAL9.8OpenZepplin is a library for smart contract development. In affected versions a vulnerability in TimelockController allo...
CVE-2021-39165MEDIUM6.5Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in th...
CVE-2021-39161MEDIUM5.4Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross...
CVE-2021-37715MEDIUM4.8A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior ...
CVE-2021-29862MEDIUM5.5IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to c...
CVE-2021-29801HIGH7.8IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to gain ...
CVE-2021-29772CRITICAL9.8IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IB...
CVE-2021-29727MEDIUM5.5IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial o...
CVE-2021-29715CRITICAL9.1IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive information or conduct denial of...
CVE-2021-32648CRITICAL9.1octobercms in a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now