2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26260 | MEDIUM | 5.5 | 1.1% | Jun 8, 2021 | An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1... |
| CVE-2021-23215 | MEDIUM | 5.5 | 1.2% | Jun 8, 2021 | An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1... |
| CVE-2021-23169 | HIGH | 8.8 | 2.3% | Jun 8, 2021 | A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker co... |
| CVE-2021-22116 | HIGH | 7.5 | 1.4% | Jun 8, 2021 | RabbitMQ all versions prior to 3.8.16 are prone to a denial of service vulnerability due to improper input validation in... |
| CVE-2021-33560 | HIGH | 7.5 | 2.3% | Jun 8, 2021 | Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to addres... |
| CVE-2021-31738 | MEDIUM | 6.1 | 0.9% | Jun 8, 2021 | Adiscon LogAnalyzer 4.1.10 and 4.1.11 allow login.php XSS. |
| CVE-2021-23392 | HIGH | 7.5 | 1.9% | Jun 8, 2021 | The package locutus before 2.0.15 are vulnerable to Regular Expression Denial of Service (ReDoS) via the gopher_parsedir... |
| CVE-2021-28811 | HIGH | 7.2 | 1.5% | Jun 8, 2021 | If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has... |
| CVE-2021-28810 | HIGH | 7.5 | 1.0% | Jun 8, 2021 | If exploited, this vulnerability allows an attacker to access resources which are not otherwise accessible without prope... |
| CVE-2021-26080 | MEDIUM | 6.1 | 0.9% | Jun 7, 2021 | EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version... |
| CVE-2021-26079 | MEDIUM | 6.1 | 0.9% | Jun 7, 2021 | The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 be... |
| CVE-2021-26078 | MEDIUM | 6.1 | 3.8% | Jun 7, 2021 | The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before... |
| CVE-2021-3277 | HIGH | 7.2 | 54.6% | Jun 7, 2021 | Nagios XI 5.7.5 and earlier allows authenticated admins to upload arbitrary files due to improper validation of the rena... |
| CVE-2021-32671 | CRITICAL | 10 | 39.7% | Jun 7, 2021 | Flarum is a forum software for building communities. Flarum's translation system allowed for string inputs to be convert... |
| CVE-2021-32670 | MEDIUM | 6.1 | 1.0% | Jun 7, 2021 | Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette... |
| CVE-2021-29504 | HIGH | 7.4 | 1.3% | Jun 7, 2021 | WP-CLI is the command-line interface for WordPress. An improper error handling in HTTPS requests management in WP-CLI ve... |
| CVE-2021-23391 | HIGH | 7.1 | 0.4% | Jun 7, 2021 | This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary f... |
| CVE-2021-20259 | HIGH | 7.8 | 0.3% | Jun 7, 2021 | A flaw was found in the Foreman project. The Proxmox compute resource exposes the password through the API to an authent... |
| CVE-2021-30543 | HIGH | 8.8 | 0.8% | Jun 7, 2021 | Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a... |
| CVE-2021-30542 | HIGH | 8.8 | 0.8% | Jun 7, 2021 | Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a... |
| CVE-2021-30540 | MEDIUM | 6.5 | 1.4% | Jun 7, 2021 | Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform... |
| CVE-2021-30539 | MEDIUM | 5.4 | 1.3% | Jun 7, 2021 | Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac... |
| CVE-2021-30538 | MEDIUM | 4.3 | 15.7% | Jun 7, 2021 | Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac... |
| CVE-2021-30537 | MEDIUM | 4.3 | 1.1% | Jun 7, 2021 | Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass co... |
| CVE-2021-30536 | HIGH | 8.1 | 1.2% | Jun 7, 2021 | Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack c... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now