2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-23986 | MEDIUM | 6.5 | 0.4% | Mar 31, 2021 | A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a c... |
| CVE-2021-23985 | MEDIUM | 6.5 | 1.4% | Mar 31, 2021 | If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the D... |
| CVE-2021-23984 | MEDIUM | 6.5 | 1.1% | Mar 31, 2021 | A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address... |
| CVE-2021-23983 | MEDIUM | 6.5 | 0.7% | Mar 31, 2021 | By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applie... |
| CVE-2021-23982 | MEDIUM | 6.5 | 0.7% | Mar 31, 2021 | Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network'... |
| CVE-2021-23981 | HIGH | 8.1 | 1.1% | Mar 31, 2021 | A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack i... |
| CVE-2021-21782 | HIGH | 8.8 | 1.3% | Mar 31, 2021 | An out-of-bounds write vulnerability exists in the SGI format buffer size processing functionality of Accusoft ImageGear... |
| CVE-2021-21776 | HIGH | 8.8 | 1.3% | Mar 31, 2021 | An out-of-bounds write vulnerability exists in the SGI Format Buffer Size Processing functionality of Accusoft ImageGear... |
| CVE-2021-21773 | HIGH | 7.8 | 0.7% | Mar 31, 2021 | An out-of-bounds write vulnerability exists in the TIFF header count-processing functionality of Accusoft ImageGear 19.8... |
| CVE-2021-28657 | MEDIUM | 5.5 | 2.8% | Mar 31, 2021 | A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apac... |
| CVE-2021-21413 | CRITICAL | 9.6 | 0.7% | Mar 30, 2021 | isolated-vm is a library for nodejs which gives you access to v8's Isolate interface. Versions of isolated-vm before v4.... |
| CVE-2021-29650 | MEDIUM | 5.5 | 0.4% | Mar 30, 2021 | An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial o... |
| CVE-2021-29649 | MEDIUM | 5.5 | 0.3% | Mar 30, 2021 | An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak,... |
| CVE-2021-29648 | MEDIUM | 5.5 | 0.3% | Mar 30, 2021 | An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_i... |
| CVE-2021-29647 | MEDIUM | 5.5 | 0.4% | Mar 30, 2021 | An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain s... |
| CVE-2021-29646 | MEDIUM | 5.5 | 0.3% | Mar 30, 2021 | An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly va... |
| CVE-2021-29642 | MEDIUM | 5.3 | 0.9% | Mar 30, 2021 | GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of Git... |
| CVE-2021-3476 | MEDIUM | 5.3 | 1.8% | Mar 30, 2021 | A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to ... |
| CVE-2021-3475 | MEDIUM | 5.3 | 1.8% | Mar 30, 2021 | There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by O... |
| CVE-2021-3474 | MEDIUM | 5.3 | 1.8% | Mar 30, 2021 | There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a... |
| CVE-2021-26579 | MEDIUM | 5.5 | 0.2% | Mar 30, 2021 | A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information... |
| CVE-2021-21412 | HIGH | 8.8 | 1.3% | Mar 30, 2021 | Potential for arbitrary code execution in npm package @thi.ng/egf `#gpg`-tagged property values (only if `decrypt: true`... |
| CVE-2021-20520 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2021-20518 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2021-20506 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now