2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22543 | HIGH | 7.8 | 0.7% | May 26, 2021 | An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and ... |
| CVE-2021-29253 | MEDIUM | 5.5 | 0.2% | May 26, 2021 | The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential st... |
| CVE-2021-29252 | MEDIUM | 5.4 | 0.8% | May 26, 2021 | RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user... |
| CVE-2021-31924 | MEDIUM | 6.8 | 0.3% | May 26, 2021 | Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, cou... |
| CVE-2021-33575 | CRITICAL | 9.8 | 2.6% | May 25, 2021 | The Pixar ruby-jss gem before 1.6.0 allows remote attackers to execute arbitrary code because of the Plist gem's documen... |
| CVE-2021-33574 | CRITICAL | 9.8 | 2.9% | May 25, 2021 | The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the noti... |
| CVE-2021-33570 | MEDIUM | 5.4 | 3.6% | May 25, 2021 | Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can ... |
| CVE-2021-20209 | HIGH | 7.5 | 1.9% | May 25, 2021 | A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are c... |
| CVE-2021-32640 | MEDIUM | 5.3 | 2.9% | May 25, 2021 | ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Pr... |
| CVE-2021-27562 | MEDIUM | 5.5 | 3.1% | May 25, 2021 | In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the print... |
| CVE-2021-25946 | CRITICAL | 9.8 | 3.3% | May 25, 2021 | Prototype pollution vulnerability in `nconf-toml` versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of s... |
| CVE-2021-25944 | CRITICAL | 9.8 | 3.0% | May 25, 2021 | Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of s... |
| CVE-2021-25935 | MEDIUM | 5.4 | 0.9% | May 25, 2021 | In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2... |
| CVE-2021-25934 | MEDIUM | 5.4 | 1.0% | May 25, 2021 | In OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2... |
| CVE-2021-3320 | HIGH | 7.5 | 0.8% | May 25, 2021 | Type Confusion in 802154 ACK Frames Handling. Zephyr versions >= v2.4.0 contain NULL Pointer Dereference (CWE-476). For ... |
| CVE-2021-32638 | MEDIUM | 4.4 | 0.4% | May 25, 2021 | Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub a... |
| CVE-2021-29708 | MEDIUM | 6.7 | 0.3% | May 25, 2021 | IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic ke... |
| CVE-2021-29695 | MEDIUM | 6.5 | 2.3% | May 25, 2021 | IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker ... |
| CVE-2021-23937 | HIGH | 7.5 | 4.3% | May 25, 2021 | A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trig... |
| CVE-2021-21660 | MEDIUM | 5.4 | 1.1% | May 25, 2021 | Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cr... |
| CVE-2021-21659 | HIGH | 8.1 | 66.8% | May 25, 2021 | Jenkins URLTrigger Plugin 0.48 and earlier does not configure its XML parser to prevent XML external entity (XXE) attack... |
| CVE-2021-21658 | CRITICAL | 9.1 | 1.5% | May 25, 2021 | Jenkins Nuget Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. |
| CVE-2021-21657 | HIGH | 8.8 | 1.6% | May 25, 2021 | Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE... |
| CVE-2021-29211 | MEDIUM | 4.8 | 0.6% | May 25, 2021 | A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrate... |
| CVE-2021-29210 | MEDIUM | 4.8 | 0.5% | May 25, 2021 | A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now