2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-29522MEDIUM5.5TensorFlow is an end-to-end open source platform for machine learning. The `tf.raw_ops.Conv3DBackprop*` operations fail ...
CVE-2021-29521MEDIUM5.5TensorFlow is an end-to-end open source platform for machine learning. Specifying a negative dense shape in `tf.raw_ops....
CVE-2021-29520HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. Missing validation between arguments to `tf.raw_o...
CVE-2021-29519MEDIUM5.5TensorFlow is an end-to-end open source platform for machine learning. The API of `tf.raw_ops.SparseCross` allows combin...
CVE-2021-29518HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. In eager mode (default in TF 2.0 and later), sess...
CVE-2021-29517MEDIUM5.5TensorFlow is an end-to-end open source platform for machine learning. A malicious user could trigger a division by 0 in...
CVE-2021-29516MEDIUM5.5TensorFlow is an end-to-end open source platform for machine learning. Calling `tf.raw_ops.RaggedTensorToVariant` with a...
CVE-2021-29515HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. The implementation of `MatrixDiag*` operations(ht...
CVE-2021-29514HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does...
CVE-2021-29513HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. Calling TF operations with tensors of non-numeric...
CVE-2021-32820HIGH8.6Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine conf...
CVE-2021-32819HIGH8.8Squirrelly is a template engine implemented in JavaScript that works out of the box with ExpressJS. Squirrelly mixes pur...
CVE-2021-32818MEDIUM5.4haml-coffee is a JavaScript templating solution. haml-coffee mixes pure template data with engine configuration options ...
CVE-2021-32817MEDIUM6.8express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration opt...
CVE-2021-29554MEDIUM5.5TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a F...
CVE-2021-29512HIGH7.8TensorFlow is an end-to-end open source platform for machine learning. If the `splits` argument of `RaggedBincount` does...
CVE-2021-32816HIGH7.5ProtonMail Web Client is the official AngularJS web client for the ProtonMail secure email service. ProtonMail Web Clien...
CVE-2021-20565MEDIUM5.3IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 uses a protection mechanism that relie...
CVE-2021-20564MEDIUM5.9IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtai...
CVE-2021-20429MEDIUM5.3IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cro...
CVE-2021-20393HIGH7.5IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could allow a remote attacker to obtain sensitive information whe...
CVE-2021-20392MEDIUM6.1IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2021-20391LOW3.3IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 allows web pages to be stored locally which can be read by anothe...
CVE-2021-25943CRITICAL9.8Prototype pollution vulnerability in '101' versions 1.0.0 through 1.6.3 allows an attacker to cause a denial of service ...
CVE-2021-25941CRITICAL9.8Prototype pollution vulnerability in 'deep-override' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial o...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now