2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3772 | MEDIUM | 6.5 | 1.2% | Mar 2, 2022 | A flaw was found in the Linux SCTP stack. A blind attacker may be able to kill an existing SCTP association through inva... |
| CVE-2021-3677 | MEDIUM | 6.5 | 1.4% | Mar 2, 2022 | A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default config... |
| CVE-2021-3667 | MEDIUM | 6.5 | 1.3% | Mar 2, 2022 | An improper locking issue was found in the virStoragePoolLookupByTargetPath API of libvirt. It occurs in the storagePool... |
| CVE-2021-3658 | MEDIUM | 6.5 | 0.8% | Mar 2, 2022 | bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it whe... |
| CVE-2021-3654 | MEDIUM | 6.1 | 27.5% | Mar 2, 2022 | A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to ... |
| CVE-2021-3631 | MEDIUM | 6.3 | 0.5% | Mar 2, 2022 | A flaw was found in libvirt while it generates SELinux MCS category pairs for VMs' dynamic labels. This flaw allows one ... |
| CVE-2021-3623 | MEDIUM | 6.1 | 0.3% | Mar 2, 2022 | A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal val... |
| CVE-2021-23222 | MEDIUM | 5.9 | 1.5% | Mar 2, 2022 | A man-in-the-middle attacker can inject false responses to the client's first few queries, despite the use of SSL certif... |
| CVE-2021-45074 | MEDIUM | 5.4 | 0.6% | Mar 2, 2022 | JFrog Artifactory before 7.29.3 and 6.23.38, is vulnerable to Broken Access Control, a low-privileged user is able to de... |
| CVE-2021-41003 | MEDIUM | 6.1 | 0.8% | Mar 2, 2022 | Multiple unauthenticated command injection vulnerabilities were discovered in the AOS-CX API interface in Aruba CX 6200F... |
| CVE-2021-38268 | MEDIUM | 6.5 | 1.1% | Mar 2, 2022 | The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.6, and Liferay DXP 7.0 before fix pack 101, 7.1 befo... |
| CVE-2021-43070 | MEDIUM | 6.5 | 0.5% | Mar 2, 2022 | Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and be... |
| CVE-2021-38996 | MEDIUM | 5.5 | 0.2% | Mar 2, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel... |
| CVE-2021-44166 | MEDIUM | 4.1 | 0.6% | Mar 2, 2022 | An improper access control vulnerability [CWE-284 ] in FortiToken Mobile (Android) external push notification 5.1.0 and ... |
| CVE-2021-45864 | MEDIUM | 5.5 | 0.7% | Mar 2, 2022 | tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp... |
| CVE-2021-45863 | MEDIUM | 5.5 | 0.7% | Mar 2, 2022 | tsMuxer git-2678966 was discovered to contain a heap-based buffer overflow via the function HevcUnit::updateBits in hevc... |
| CVE-2021-45861 | MEDIUM | 5.5 | 0.7% | Mar 2, 2022 | There is an Assertion `num <= INT_BIT' failed at BitStreamReader::skipBits in /bitStream.h:132 of tsMuxer git-c6a0277. |
| CVE-2021-45860 | MEDIUM | 5.5 | 0.7% | Mar 2, 2022 | An integer overflow in DTSStreamReader::findFrame() of tsMuxer git-2678966 allows attackers to cause a Denial of Service... |
| CVE-2021-38986 | MEDIUM | 5.4 | 0.4% | Mar 1, 2022 | IBM MQ Appliance 9.2 CD and 9.2 LTS does not invalidate session after logout which could allow an authenticated user to ... |
| CVE-2021-38955 | MEDIUM | 4.4 | 0.2% | Mar 1, 2022 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a local user with elevated privileges to cause a denial of service due t... |
| CVE-2021-46387 | MEDIUM | 6.1 | 21.0% | Mar 1, 2022 | ZyXEL ZyWALL 2 Plus Internet Security Appliance is affected by Cross Site Scripting (XSS). Insecure URI handling leads t... |
| CVE-2021-44747 | MEDIUM | 6.5 | 0.6% | Mar 1, 2022 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Linux Security whereby the Fmlib component used in ce... |
| CVE-2021-35036 | MEDIUM | 6.5 | 0.5% | Mar 1, 2022 | A cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow... |
| CVE-2021-44962 | MEDIUM | 5.5 | 0.9% | Mar 1, 2022 | An out-of-bounds read vulnerability exists in the GCode::extrude() functionality of Slic3r libslic3r 1.3.0 and Master Co... |
| CVE-2021-44961 | MEDIUM | 5.5 | 0.9% | Mar 1, 2022 | A memory leakage flaw exists in the class PerimeterGenerator of Slic3r libslic3r 1.3.0 and Master Commit b1a5500. Specia... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now