2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3392LOW3.2A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests i...
CVE-2021-27908MEDIUM4.4In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an au...
CVE-2021-21402MEDIUM6.5Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted reques...
CVE-2021-3444HIGH7.8The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source regis...
CVE-2021-21401HIGH7.1Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, deco...
CVE-2021-23362MEDIUM5.3The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expr...
CVE-2021-23274CRITICAL9.8The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution ...
CVE-2021-20270HIGH7.5An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax high...
CVE-2021-20227MEDIUM5.5A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of r...
CVE-2021-20222HIGH7.5A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the refe...
CVE-2021-20219MEDIUM5.5A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In...
CVE-2021-21377MEDIUM5.4OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports ...
CVE-2021-21376MEDIUM6.5OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads var...
CVE-2021-27969MEDIUM4.8Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.
CVE-2021-27531MEDIUM4.8A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "...
CVE-2021-27530MEDIUM4.8A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in ...
CVE-2021-27529MEDIUM4.8A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "...
CVE-2021-27528MEDIUM4.8A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "...
CVE-2021-27527MEDIUM4.8A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "...
CVE-2021-27526MEDIUM4.8A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "...
CVE-2021-27310MEDIUM6.1Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter.
CVE-2021-27309MEDIUM6.1Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter.
CVE-2021-23361Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-29082HIGH8.8Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBW30 before 2.6.1.4, RBS40V b...
CVE-2021-29081HIGH8.4Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects RBW30...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now