2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26260MEDIUM5.5An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1...
CVE-2021-23215MEDIUM5.5An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1...
CVE-2021-23169HIGH8.8A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker co...
CVE-2021-22116HIGH7.5RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in...
CVE-2021-33560HIGH7.5Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to addres...
CVE-2021-31738MEDIUM6.1Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS.
CVE-2021-23392HIGH7.5The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir...
CVE-2021-28811HIGH7.2If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has...
CVE-2021-28810HIGH7.5If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without prope...
CVE-2021-26080MEDIUM6.1EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version...
CVE-2021-26079MEDIUM6.1The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 be...
CVE-2021-26078MEDIUM6.1The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before...
CVE-2021-3277HIGH7.2Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rena...
CVE-2021-32671CRITICAL10Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be convert...
CVE-2021-32670MEDIUM6.1Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette...
CVE-2021-29504HIGH7.4WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI ve...
CVE-2021-23391HIGH7.1This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary f...
CVE-2021-20259HIGH7.8A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authent...
CVE-2021-30543HIGH8.8Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a...
CVE-2021-30542HIGH8.8Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a...
CVE-2021-30540MEDIUM6.5Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform...
CVE-2021-30539MEDIUM5.4Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac...
CVE-2021-30538MEDIUM4.3Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac...
CVE-2021-30537MEDIUM4.3Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass co...
CVE-2021-30536HIGH8.1Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack c...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now