2021 CVE Vulnerabilities

23,466 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-34374MEDIUM6.7Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerabilit...
CVE-2021-34373MEDIUM6Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could...
CVE-2021-31721MEDIUM6.1Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.
CVE-2021-30648CRITICAL9.8The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypa...
CVE-2021-28693MEDIUM5.5xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary ...
CVE-2021-28692HIGH7.1inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operati...
CVE-2021-25321HIGH7.8A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Man...
CVE-2021-35474CRITICAL9.8Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic...
CVE-2021-32567HIGH7.5Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This is...
CVE-2021-32566HIGH7.5Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This is...
CVE-2021-35959MEDIUM5.4In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a fo...
CVE-2021-35958CRITICAL9.1TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_fil...
CVE-2021-35941HIGH7.5Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that ca...
CVE-2021-22341MEDIUM4.9There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers wi...
CVE-2021-22329MEDIUM4.9There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform s...
CVE-2021-32721MEDIUM6.1PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to ...
CVE-2021-29485HIGH8.8Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote ...
CVE-2021-29481HIGH7.5Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side...
CVE-2021-29480LOW3.1Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the client side session module uses the ...
CVE-2021-22439HIGH8.1There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request t...
CVE-2021-22340MEDIUM4.1There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O r...
CVE-2021-22338MEDIUM5.3There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict ope...
CVE-2021-20079MEDIUM6.7Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus...
CVE-2021-28830HIGH7.8The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtim...
CVE-2021-23275HIGH7.8The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enter...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now