2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20371 | MEDIUM | 6.5 | 1.2% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an e... |
| CVE-2021-20348 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20347 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20346 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20345 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20343 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an... |
| CVE-2021-20338 | MEDIUM | 5.4 | 0.5% | Jun 2, 2021 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-32625 | HIGH | 8.8 | 4.4% | Jun 2, 2021 | Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. A... |
| CVE-2021-3529 | HIGH | 7.1 | 0.7% | Jun 2, 2021 | A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copi... |
| CVE-2021-30474 | CRITICAL | 9.8 | 1.9% | Jun 2, 2021 | aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free. |
| CVE-2021-3499 | MEDIUM | 5.6 | 0.8% | Jun 2, 2021 | A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not rel... |
| CVE-2021-3468 | MEDIUM | 5.5 | 0.4% | Jun 2, 2021 | A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection o... |
| CVE-2021-31921 | CRITICAL | 9.8 | 1.5% | Jun 2, 2021 | Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can acc... |
| CVE-2021-31855 | MEDIUM | 6.5 | 0.6% | Jun 2, 2021 | KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a de... |
| CVE-2021-28678 | MEDIUM | 5.5 | 0.7% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after ju... |
| CVE-2021-28677 | HIGH | 7.5 | 2.3% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to de... |
| CVE-2021-28676 | HIGH | 7.5 | 2.5% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance wa... |
| CVE-2021-25288 | CRITICAL | 9.1 | 2.3% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i. |
| CVE-2021-25287 | CRITICAL | 9.1 | 2.9% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la. |
| CVE-2021-3530 | HIGH | 7.5 | 2.4% | Jun 2, 2021 | A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version... |
| CVE-2021-3522 | MEDIUM | 5.5 | 5.4% | Jun 2, 2021 | GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags. |
| CVE-2021-28675 | MEDIUM | 5.5 | 1.0% | Jun 2, 2021 | An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input... |
| CVE-2021-26707 | CRITICAL | 9.8 | 1.9% | Jun 2, 2021 | The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding... |
| CVE-2021-3546 | HIGH | 8.2 | 0.5% | Jun 2, 2021 | An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions ... |
| CVE-2021-3545 | MEDIUM | 6.5 | 0.4% | Jun 2, 2021 | An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versio... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now