2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21229 | MEDIUM | 6.5 | 0.9% | Apr 30, 2021 | Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perfor... |
| CVE-2021-21228 | MEDIUM | 4.3 | 1.1% | Apr 30, 2021 | Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a... |
| CVE-2021-21227 | HIGH | 8.8 | 1.2% | Apr 30, 2021 | Insufficient data validation in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially explo... |
| CVE-2021-31926 | MEDIUM | 6.5 | 0.9% | Apr 30, 2021 | AMP Application Deployment Service in CubeCoders AMP 2.1.x before 2.1.1.2 allows a remote, authenticated user to open po... |
| CVE-2021-29464 | HIGH | 7.8 | 1.5% | Apr 30, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-29463 | MEDIUM | 5.5 | 1.1% | Apr 30, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-29486 | HIGH | 7.5 | 2.0% | Apr 30, 2021 | cumulative-distribution-function is an open source npm library used which calculates statistical cumulative distribution... |
| CVE-2021-21537 | MEDIUM | 5.5 | 0.2% | Apr 30, 2021 | Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker... |
| CVE-2021-21536 | MEDIUM | 5.5 | 0.2% | Apr 30, 2021 | Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker... |
| CVE-2021-21535 | HIGH | 7.8 | 0.2% | Apr 30, 2021 | Dell Hybrid Client versions prior to 1.5 contain a missing authentication for a critical function vulnerability. A local... |
| CVE-2021-21534 | LOW | 3.3 | 0.2% | Apr 30, 2021 | Dell Hybrid Client versions prior to 1.5 contain an information exposure vulnerability. A local unauthenticated attacker... |
| CVE-2021-20515 | MEDIUM | 6.7 | 0.3% | Apr 30, 2021 | IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A ... |
| CVE-2021-31232 | MEDIUM | 5.5 | 0.4% | Apr 30, 2021 | The Alertmanager in CNCF Cortex before 1.8.1 has a local file disclosure vulnerability when -experimental.alertmanager.e... |
| CVE-2021-31231 | MEDIUM | 5.5 | 0.3% | Apr 30, 2021 | The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vul... |
| CVE-2021-28959 | CRITICAL | 9.8 | 16.9% | Apr 30, 2021 | Zoho ManageEngine Eventlog Analyzer through 12147 is vulnerable to unauthenticated directory traversal via an entry in a... |
| CVE-2021-20266 | MEDIUM | 4.9 | 1.7% | Apr 30, 2021 | A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause ... |
| CVE-2021-26807 | HIGH | 7.8 | 0.5% | Apr 30, 2021 | GalaxyClient version 2.0.28.9 loads unsigned DLLs such as zlib1.dll, libgcc_s_dw2-1.dll and libwinpthread-1.dll from PAT... |
| CVE-2021-20326 | MEDIUM | 6.5 | 0.9% | Apr 30, 2021 | A user authorized to performing a specific type of find query may trigger a denial of service. This issue affects MongoD... |
| CVE-2021-31873 | CRITICAL | 9.8 | 2.1% | Apr 30, 2021 | An issue was discovered in klibc before 2.0.9. Additions in the malloc() function may result in an integer overflow and ... |
| CVE-2021-31872 | CRITICAL | 9.8 | 2.1% | Apr 30, 2021 | An issue was discovered in klibc before 2.0.9. Multiple possible integer overflows in the cpio command on 32-bit systems... |
| CVE-2021-31871 | HIGH | 7.5 | 1.9% | Apr 30, 2021 | An issue was discovered in klibc before 2.0.9. An integer overflow in the cpio command may result in a NULL pointer dere... |
| CVE-2021-31870 | CRITICAL | 9.8 | 2.1% | Apr 30, 2021 | An issue was discovered in klibc before 2.0.9. Multiplication in the calloc() function may result in an integer overflow... |
| CVE-2021-31919 | HIGH | 7.5 | 1.1% | Apr 30, 2021 | An issue was discovered in the rkyv crate before 0.6.0 for Rust. When an archive is created via serialization, the archi... |
| CVE-2021-29484 | MEDIUM | 6.8 | 7.9% | Apr 29, 2021 | Ghost is a Node.js CMS. An unused endpoint added during the development of 4.0.0 has left sites vulnerable to untrusted ... |
| CVE-2021-29468 | HIGH | 8.8 | 1.2% | Apr 29, 2021 | Cygwin Git is a patch set for the git command line tool for the cygwin environment. A specially crafted repository that ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now