2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3544 | MEDIUM | 6.5 | 0.4% | Jun 2, 2021 | Several memory leaks were found in the virtio vhost-user GPU device (vhost-user-gpu) of QEMU in versions up to and inclu... |
| CVE-2021-3538 | CRITICAL | 9.8 | 2.3% | Jun 2, 2021 | A flaw was found in github.com/satori/go.uuid in versions from commit 0ef6afb2f6cdd6cdaeee3885a95099c63f18fc8c to d91630... |
| CVE-2021-23896 | MEDIUM | 4.5 | 0.2% | Jun 2, 2021 | Cleartext Transmission of Sensitive Information vulnerability in the administrator interface of McAfee Database Security... |
| CVE-2021-3520 | CRITICAL | 9.8 | 3.2% | Jun 2, 2021 | There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger a... |
| CVE-2021-26940 | — | — | — | Jun 2, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-33500. Reason: This candidate is a reservation d... |
| CVE-2021-24012 | HIGH | 7.3 | 0.5% | Jun 2, 2021 | An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an ... |
| CVE-2021-23895 | HIGH | 8 | 1.9% | Jun 2, 2021 | Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote authe... |
| CVE-2021-23894 | HIGH | 8.8 | 2.2% | Jun 2, 2021 | Deserialization of untrusted data vulnerability in McAfee Database Security (DBSec) prior to 4.8.2 allows a remote unaut... |
| CVE-2021-29089 | CRITICAL | 9.8 | 1.9% | Jun 2, 2021 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in thumbnail componen... |
| CVE-2021-29091 | MEDIUM | 6.5 | 1.1% | Jun 2, 2021 | Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in file management componen... |
| CVE-2021-29090 | HIGH | 7.2 | 1.7% | Jun 2, 2021 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in PHP component in S... |
| CVE-2021-32657 | MEDIUM | 4.3 | 1.8% | Jun 1, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions of Nextcloud Server prior to 10.0.11, 20.... |
| CVE-2021-32656 | HIGH | 8.6 | 1.8% | Jun 1, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions... |
| CVE-2021-32655 | LOW | 3.5 | 1.0% | Jun 1, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an... |
| CVE-2021-32654 | CRITICAL | 9.1 | 1.8% | Jun 1, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an... |
| CVE-2021-3425 | MEDIUM | 4.4 | 0.3% | Jun 1, 2021 | A flaw was found in the AMQ Broker that discloses JDBC encrypted usernames and passwords when provided in the AMQ Broker... |
| CVE-2021-32653 | LOW | 2.7 | 1.2% | Jun 1, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10, ... |
| CVE-2021-31684 | HIGH | 7.5 | 2.3% | Jun 1, 2021 | A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which c... |
| CVE-2021-26111 | MEDIUM | 6.5 | 0.4% | Jun 1, 2021 | A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 ... |
| CVE-2021-22123 | HIGH | 8.8 | 77.3% | Jun 1, 2021 | An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x,... |
| CVE-2021-3424 | MEDIUM | 5.3 | 0.8% | Jun 1, 2021 | A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malici... |
| CVE-2021-32652 | MEDIUM | 4.3 | 1.1% | Jun 1, 2021 | Nextcloud Mail is a mail app for the Nextcloud platform. A missing permission check in Nextcloud Mail before 1.4.3 and 1... |
| CVE-2021-32924 | HIGH | 8.8 | 19.9% | Jun 1, 2021 | Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because th... |
| CVE-2021-32651 | MEDIUM | 4.3 | 1.1% | Jun 1, 2021 | OneDev is a development operations platform. If the LDAP external authentication mechanism is enabled in OneDev versions... |
| CVE-2021-31643 | MEDIUM | 5.4 | 88.4% | Jun 1, 2021 | An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now