2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29522 | MEDIUM | 5.5 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. The `tf.raw_ops.Conv3DBackprop*` operations fail ... |
| CVE-2021-29521 | MEDIUM | 5.5 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops.... |
| CVE-2021-29520 | HIGH | 7.8 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. Missing validation between arguments to `tf.raw_o... |
| CVE-2021-29519 | MEDIUM | 5.5 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. The API of `tf.raw_ops.SparseCross` allows combin... |
| CVE-2021-29518 | HIGH | 7.8 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In eager mode (default in TF 2.0 and later), sess... |
| CVE-2021-29517 | MEDIUM | 5.5 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. A malicious user could trigger a division by 0 in... |
| CVE-2021-29516 | MEDIUM | 5.5 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. Calling `tf.raw_ops.RaggedTensorToVariant` with a... |
| CVE-2021-29515 | HIGH | 7.8 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. The implementation of `MatrixDiag*` operations(ht... |
| CVE-2021-29514 | HIGH | 7.8 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does... |
| CVE-2021-29513 | HIGH | 7.8 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. Calling TF operations with tensors of non-numeric... |
| CVE-2021-32820 | HIGH | 8.6 | 18.0% | May 14, 2021 | Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine conf... |
| CVE-2021-32819 | HIGH | 8.8 | 59.8% | May 14, 2021 | Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pur... |
| CVE-2021-32818 | MEDIUM | 5.4 | 0.7% | May 14, 2021 | haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options ... |
| CVE-2021-32817 | MEDIUM | 6.8 | 1.3% | May 14, 2021 | express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration opt... |
| CVE-2021-29554 | MEDIUM | 5.5 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a F... |
| CVE-2021-29512 | HIGH | 7.8 | 0.2% | May 14, 2021 | TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does... |
| CVE-2021-32816 | HIGH | 7.5 | 1.0% | May 14, 2021 | ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Clien... |
| CVE-2021-20565 | MEDIUM | 5.3 | 0.8% | May 14, 2021 | IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 uses a protection mechanism that relie... |
| CVE-2021-20564 | MEDIUM | 5.9 | 0.9% | May 14, 2021 | IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtai... |
| CVE-2021-20429 | MEDIUM | 5.3 | 0.8% | May 14, 2021 | IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cro... |
| CVE-2021-20393 | HIGH | 7.5 | 1.4% | May 14, 2021 | IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information whe... |
| CVE-2021-20392 | MEDIUM | 6.1 | 0.7% | May 14, 2021 | IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows ... |
| CVE-2021-20391 | LOW | 3.3 | 0.2% | May 14, 2021 | IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by anothe... |
| CVE-2021-25943 | CRITICAL | 9.8 | 3.3% | May 14, 2021 | Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service ... |
| CVE-2021-25941 | CRITICAL | 9.8 | 3.3% | May 14, 2021 | Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial o... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now