2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28952 | HIGH | 7.8 | 0.4% | Mar 20, 2021 | An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a bu... |
| CVE-2021-28117 | HIGH | 7.5 | 1.6% | Mar 20, 2021 | libdiscover/backends/KNSBackend/KNSResource.cpp in KDE Discover before 5.21.3 automatically creates links to potentially... |
| CVE-2021-28951 | MEDIUM | 5.5 | 0.3% | Mar 20, 2021 | An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of se... |
| CVE-2021-28950 | MEDIUM | 5.5 | 0.4% | Mar 20, 2021 | An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retr... |
| CVE-2021-21267 | HIGH | 7.5 | 2.1% | Mar 19, 2021 | Schema-Inspector is an open-source tool to sanitize and validate JS objects (npm package schema-inspector). In before ve... |
| CVE-2021-27520 | MEDIUM | 6.1 | 6.4% | Mar 19, 2021 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "... |
| CVE-2021-27519 | MEDIUM | 6.1 | 7.6% | Mar 19, 2021 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "... |
| CVE-2021-26992 | HIGH | 7.5 | 1.4% | Mar 19, 2021 | Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability which could allow a remote attacker to cause a ... |
| CVE-2021-26991 | HIGH | 7.5 | 1.2% | Mar 19, 2021 | Cloud Manager versions prior to 3.9.4 contain an insecure Cross-Origin Resource Sharing (CORS) policy which could allow ... |
| CVE-2021-26990 | CRITICAL | 9.1 | 1.5% | Mar 19, 2021 | Cloud Manager versions prior to 3.9.4 are susceptible to a vulnerability that could allow a remote attacker to overwrite... |
| CVE-2021-20077 | MEDIUM | 6.7 | 0.3% | Mar 19, 2021 | Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local h... |
| CVE-2021-25278 | MEDIUM | 4.8 | 0.6% | Mar 19, 2021 | FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template ... |
| CVE-2021-25277 | MEDIUM | 6.1 | 0.8% | Mar 19, 2021 | FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component. |
| CVE-2021-27906 | MEDIUM | 5.5 | 3.3% | Mar 19, 2021 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFB... |
| CVE-2021-27807 | MEDIUM | 5.5 | 3.0% | Mar 19, 2021 | A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox versi... |
| CVE-2021-21390 | MEDIUM | 5.9 | 0.9% | Mar 19, 2021 | MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage se... |
| CVE-2021-21387 | HIGH | 7.5 | 0.4% | Mar 19, 2021 | Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.... |
| CVE-2021-27506 | MEDIUM | 5.5 | 1.3% | Mar 19, 2021 | The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to Do... |
| CVE-2021-28834 | CRITICAL | 9.8 | 2.8% | Mar 19, 2021 | Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes ... |
| CVE-2021-28831 | HIGH | 7.5 | 2.8% | Mar 19, 2021 | decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultan... |
| CVE-2021-28090 | MEDIUM | 5.3 | 2.1% | Mar 19, 2021 | Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TR... |
| CVE-2021-28089 | HIGH | 7.5 | 1.7% | Mar 19, 2021 | Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka T... |
| CVE-2021-28126 | MEDIUM | 6.1 | 0.6% | Mar 19, 2021 | index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vuln... |
| CVE-2021-28110 | HIGH | 7.5 | 1.0% | Mar 19, 2021 | /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser. |
| CVE-2021-25293 | HIGH | 7.5 | 1.6% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. There is an out-of-bounds read in SGIRleDecode.c. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now