2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3392 | LOW | 3.2 | 0.4% | Mar 23, 2021 | A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests i... |
| CVE-2021-27908 | MEDIUM | 4.4 | 0.3% | Mar 23, 2021 | In all versions prior to Mautic 3.3.2, secret parameters such as database credentials could be exposed publicly by an au... |
| CVE-2021-21402 | MEDIUM | 6.5 | 79.9% | Mar 23, 2021 | Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted reques... |
| CVE-2021-3444 | HIGH | 7.8 | 0.6% | Mar 23, 2021 | The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source regis... |
| CVE-2021-21401 | HIGH | 7.1 | 1.8% | Mar 23, 2021 | Nanopb is a small code-size Protocol Buffers implementation in ansi C. In Nanopb before versions 0.3.9.8 and 0.4.5, deco... |
| CVE-2021-23362 | MEDIUM | 5.3 | 3.6% | Mar 23, 2021 | The package hosted-git-info before 3.0.8 are vulnerable to Regular Expression Denial of Service (ReDoS) via regular expr... |
| CVE-2021-23274 | CRITICAL | 9.8 | 1.2% | Mar 23, 2021 | The Config UI component of TIBCO Software Inc.'s TIBCO API Exchange Gateway and TIBCO API Exchange Gateway Distribution ... |
| CVE-2021-20270 | HIGH | 7.5 | 2.7% | Mar 23, 2021 | An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax high... |
| CVE-2021-20227 | MEDIUM | 5.5 | 0.5% | Mar 23, 2021 | A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of r... |
| CVE-2021-20222 | HIGH | 7.5 | 1.2% | Mar 23, 2021 | A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the refe... |
| CVE-2021-20219 | MEDIUM | 5.5 | 0.4% | Mar 23, 2021 | A denial of service vulnerability was found in n_tty_receive_char_special in drivers/tty/n_tty.c of the Linux kernel. In... |
| CVE-2021-21377 | MEDIUM | 5.4 | 0.8% | Mar 23, 2021 | OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports ... |
| CVE-2021-21376 | MEDIUM | 6.5 | 1.5% | Mar 23, 2021 | OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads var... |
| CVE-2021-27969 | MEDIUM | 4.8 | 0.7% | Mar 23, 2021 | Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter. |
| CVE-2021-27531 | MEDIUM | 4.8 | 0.8% | Mar 23, 2021 | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "... |
| CVE-2021-27530 | MEDIUM | 4.8 | 0.8% | Mar 23, 2021 | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allow remote attacker to inject javascript via URI in ... |
| CVE-2021-27529 | MEDIUM | 4.8 | 0.8% | Mar 23, 2021 | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "... |
| CVE-2021-27528 | MEDIUM | 4.8 | 0.8% | Mar 23, 2021 | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "... |
| CVE-2021-27527 | MEDIUM | 4.8 | 0.8% | Mar 23, 2021 | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "... |
| CVE-2021-27526 | MEDIUM | 4.8 | 0.8% | Mar 23, 2021 | A cross-site scripting (XSS) vulnerability in DynPG version 4.9.2 allows remote attackers to inject JavaScript via the "... |
| CVE-2021-27310 | MEDIUM | 6.1 | 2.8% | Mar 23, 2021 | Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "language" parameter. |
| CVE-2021-27309 | MEDIUM | 6.1 | 2.0% | Mar 23, 2021 | Clansphere CMS 2011.4 allows unauthenticated reflected XSS via "module" parameter. |
| CVE-2021-23361 | — | — | — | Mar 23, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2021-29082 | HIGH | 8.8 | 0.4% | Mar 23, 2021 | Certain NETGEAR devices are affected by disclosure of sensitive information. This affects RBW30 before 2.6.1.4, RBS40V b... |
| CVE-2021-29081 | HIGH | 8.4 | 0.4% | Mar 23, 2021 | Certain NETGEAR devices are affected by a stack-based buffer overflow by an unauthenticated attacker. This affects RBW30... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now