2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-23986MEDIUM6.5A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a c...
CVE-2021-23985MEDIUM6.5If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the D...
CVE-2021-23984MEDIUM6.5A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address...
CVE-2021-23983MEDIUM6.5By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applie...
CVE-2021-23982MEDIUM6.5Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network'...
CVE-2021-23981HIGH8.1A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack i...
CVE-2021-21782HIGH8.8An out-of-bounds write vulnerability exists in the SGI format buffer size processing functionality of Accusoft ImageGear...
CVE-2021-21776HIGH8.8An out-of-bounds write vulnerability exists in the SGI Format Buffer Size Processing functionality of Accusoft ImageGear...
CVE-2021-21773HIGH7.8An out-of-bounds write vulnerability exists in the TIFF header count-processing functionality of Accusoft ImageGear 19.8...
CVE-2021-28657MEDIUM5.5A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apac...
CVE-2021-21413CRITICAL9.6isolated-vm is a library for nodejs which gives you access to v8's Isolate interface. Versions of isolated-vm before v4....
CVE-2021-29650MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial o...
CVE-2021-29649MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak,...
CVE-2021-29648MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_i...
CVE-2021-29647MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain s...
CVE-2021-29646MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly va...
CVE-2021-29642MEDIUM5.3GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of Git...
CVE-2021-3476MEDIUM5.3A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to ...
CVE-2021-3475MEDIUM5.3There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by O...
CVE-2021-3474MEDIUM5.3There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a...
CVE-2021-26579MEDIUM5.5A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information...
CVE-2021-21412HIGH8.8Potential for arbitrary code execution in npm package @thi.ng/egf `#gpg`-tagged property values (only if `decrypt: true`...
CVE-2021-20520MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2021-20518MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2021-20506MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now