2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21229MEDIUM6.5Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perfor...
CVE-2021-21228MEDIUM4.3Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a...
CVE-2021-21227HIGH8.8Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially explo...
CVE-2021-31926MEDIUM6.5AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open po...
CVE-2021-29464HIGH7.8Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-29463MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-29486HIGH7.5cumulative-distribution-function is an open source npm library used which calculates statistical cumulative distribution...
CVE-2021-21537MEDIUM5.5Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker...
CVE-2021-21536MEDIUM5.5Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker...
CVE-2021-21535HIGH7.8Dell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local...
CVE-2021-21534LOW3.3Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker...
CVE-2021-20515MEDIUM6.7IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A ...
CVE-2021-31232MEDIUM5.5The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.e...
CVE-2021-31231MEDIUM5.5The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vul...
CVE-2021-28959CRITICAL9.8Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a...
CVE-2021-20266MEDIUM4.9A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause ...
CVE-2021-26807HIGH7.8GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PAT...
CVE-2021-20326MEDIUM6.5A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoD...
CVE-2021-31873CRITICAL9.8An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and ...
CVE-2021-31872CRITICAL9.8An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems...
CVE-2021-31871HIGH7.5An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dere...
CVE-2021-31870CRITICAL9.8An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow...
CVE-2021-31919HIGH7.5An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archi...
CVE-2021-29484MEDIUM6.8Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted ...
CVE-2021-29468HIGH8.8Cygwin Git is a patch set for the git command line tool for the cygwin environment. A specially crafted repository that ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now