2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20371MEDIUM6.5IBM Jazz Foundation and IBM Engineering products could allow a remote attacker to obtain sensitive information when an e...
CVE-2021-20348MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20347MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20346MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20345MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20343MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to server-side request forgery (SSRF). This may allow an...
CVE-2021-20338MEDIUM5.4IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-32625HIGH8.8Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. A...
CVE-2021-3529HIGH7.1A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copi...
CVE-2021-30474CRITICAL9.8aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free.
CVE-2021-3499MEDIUM5.6A vulnerability was found in OVN Kubernetes in versions up to and including 0.3.0 where the Egress Firewall does not rel...
CVE-2021-3468MEDIUM5.5A flaw was found in avahi in versions 0.6 up to 0.8. The event used to signal the termination of the client connection o...
CVE-2021-31921CRITICAL9.8Istio before 1.8.6 and 1.9.x before 1.9.5 contains a remotely exploitable vulnerability where an external client can acc...
CVE-2021-31855MEDIUM6.5KDE Messagelib through 5.17.0 reveals cleartext of encrypted messages in some situations. Deleting an attachment of a de...
CVE-2021-28678MEDIUM5.5An issue was discovered in Pillow before 8.2.0. For BLP data, BlpImagePlugin did not properly check that reads (after ju...
CVE-2021-28677HIGH7.5An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to de...
CVE-2021-28676HIGH7.5An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance wa...
CVE-2021-25288CRITICAL9.1An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.
CVE-2021-25287CRITICAL9.1An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.
CVE-2021-3530HIGH7.5A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version...
CVE-2021-3522MEDIUM5.5GStreamer before 1.18.4 may perform an out-of-bounds read when handling certain ID3v2 tags.
CVE-2021-28675MEDIUM5.5An issue was discovered in Pillow before 8.2.0. PSDImagePlugin.PsdImageFile lacked a sanity check on the number of input...
CVE-2021-26707CRITICAL9.8The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding...
CVE-2021-3546HIGH8.2An out-of-bounds write vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions ...
CVE-2021-3545MEDIUM6.5An information disclosure vulnerability was found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versio...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now