2021 CVE Vulnerabilities
23,466 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-34374 | MEDIUM | 6.7 | 0.2% | Jun 30, 2021 | Trusty contains a vulnerability in command handlers where the length of input buffers is not verified. This vulnerabilit... |
| CVE-2021-34373 | MEDIUM | 6 | 0.3% | Jun 30, 2021 | Trusty trusted Linux kernel (TLK) contains a vulnerability in the NVIDIA TLK kernel where a lack of heap hardening could... |
| CVE-2021-31721 | MEDIUM | 6.1 | 1.2% | Jun 30, 2021 | Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage. |
| CVE-2021-30648 | CRITICAL | 9.8 | 1.4% | Jun 30, 2021 | The Symantec Advanced Secure Gateway (ASG) and ProxySG web management consoles are susceptible to an authentication bypa... |
| CVE-2021-28693 | MEDIUM | 5.5 | 0.3% | Jun 30, 2021 | xen/arm: Boot modules are not scrubbed The bootloader will load boot modules (e.g. kernel, initramfs...) in a temporary ... |
| CVE-2021-28692 | HIGH | 7.1 | 0.3% | Jun 30, 2021 | inappropriate x86 IOMMU timeout detection / handling IOMMUs process commands issued to them in parallel with the operati... |
| CVE-2021-25321 | HIGH | 7.8 | 0.4% | Jun 30, 2021 | A UNIX Symbolic Link (Symlink) Following vulnerability in arpwatch of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Man... |
| CVE-2021-35474 | CRITICAL | 9.8 | 2.7% | Jun 30, 2021 | Stack-based Buffer Overflow vulnerability in cachekey plugin of Apache Traffic Server. This issue affects Apache Traffic... |
| CVE-2021-32567 | HIGH | 7.5 | 2.4% | Jun 30, 2021 | Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This is... |
| CVE-2021-32566 | HIGH | 7.5 | 2.5% | Jun 30, 2021 | Improper Input Validation vulnerability in HTTP/2 of Apache Traffic Server allows an attacker to DOS the server. This is... |
| CVE-2021-35959 | MEDIUM | 5.4 | 0.5% | Jun 30, 2021 | In Plone 5.0 through 5.2.4, Editors are vulnerable to XSS in the folder contents view, if a Contributor has created a fo... |
| CVE-2021-35958 | CRITICAL | 9.1 | 1.9% | Jun 30, 2021 | TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a crafted archive when tf.keras.utils.get_fil... |
| CVE-2021-35941 | HIGH | 7.5 | 12.7% | Jun 29, 2021 | Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that ca... |
| CVE-2021-22341 | MEDIUM | 4.9 | 0.6% | Jun 29, 2021 | There is a memory leak vulnerability in Huawei products. A resource management weakness exists in a module. Attackers wi... |
| CVE-2021-22329 | MEDIUM | 4.9 | 0.5% | Jun 29, 2021 | There has a license management vulnerability in some Huawei products. An attacker with high privilege needs to perform s... |
| CVE-2021-32721 | MEDIUM | 6.1 | 0.6% | Jun 29, 2021 | PowerMux is a drop-in replacement for Go's http.ServeMux. In PowerMux versions prior to 1.1.1, attackers may be able to ... |
| CVE-2021-29485 | HIGH | 8.8 | 2.0% | Jun 29, 2021 | Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a malicious attacker can achieve Remote ... |
| CVE-2021-29481 | HIGH | 7.5 | 0.5% | Jun 29, 2021 | Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the default configuration of client side... |
| CVE-2021-29480 | LOW | 3.1 | 0.3% | Jun 29, 2021 | Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, the client side session module uses the ... |
| CVE-2021-22439 | HIGH | 8.1 | 0.8% | Jun 29, 2021 | There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request t... |
| CVE-2021-22340 | MEDIUM | 4.1 | 0.1% | Jun 29, 2021 | There is a multiple threads race condition vulnerability in Huawei product. A race condition exists for concurrent I/O r... |
| CVE-2021-22338 | MEDIUM | 5.3 | 0.6% | Jun 29, 2021 | There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict ope... |
| CVE-2021-20079 | MEDIUM | 6.7 | 0.4% | Jun 29, 2021 | Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus... |
| CVE-2021-28830 | HIGH | 7.8 | 0.2% | Jun 29, 2021 | The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtim... |
| CVE-2021-23275 | HIGH | 7.8 | 0.2% | Jun 29, 2021 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enter... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now