2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-28952HIGH7.8An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a bu...
CVE-2021-28117HIGH7.5libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially...
CVE-2021-28951MEDIUM5.5An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of se...
CVE-2021-28950MEDIUM5.5An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retr...
CVE-2021-21267HIGH7.5Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before ve...
CVE-2021-27520MEDIUM6.1A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "...
CVE-2021-27519MEDIUM6.1A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "...
CVE-2021-26992HIGH7.5Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a ...
CVE-2021-26991HIGH7.5Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow ...
CVE-2021-26990CRITICAL9.1Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite...
CVE-2021-20077MEDIUM6.7Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local h...
CVE-2021-25278MEDIUM4.8FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template ...
CVE-2021-25277MEDIUM6.1FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component.
CVE-2021-27906MEDIUM5.5A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFB...
CVE-2021-27807MEDIUM5.5A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox versi...
CVE-2021-21390MEDIUM5.9MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage se...
CVE-2021-21387HIGH7.5Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0....
CVE-2021-27506MEDIUM5.5The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to Do...
CVE-2021-28834CRITICAL9.8Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes ...
CVE-2021-28831HIGH7.5decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultan...
CVE-2021-28090MEDIUM5.3Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TR...
CVE-2021-28089HIGH7.5Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka T...
CVE-2021-28126MEDIUM6.1index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vuln...
CVE-2021-28110HIGH7.5/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.
CVE-2021-25293HIGH7.5An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now