2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3947 | MEDIUM | 5.5 | 0.3% | Feb 18, 2022 | A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a maliciou... |
| CVE-2021-3930 | MEDIUM | 6.5 | 0.3% | Feb 18, 2022 | An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands... |
| CVE-2021-39026 | MEDIUM | 5.9 | 0.5% | Feb 18, 2022 | IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, ca... |
| CVE-2021-30650 | MEDIUM | 6.1 | 0.7% | Feb 18, 2022 | A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a ... |
| CVE-2021-20321 | MEDIUM | 4.7 | 0.2% | Feb 18, 2022 | A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in s... |
| CVE-2021-20320 | MEDIUM | 5.5 | 0.3% | Feb 18, 2022 | A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a l... |
| CVE-2021-20315 | MEDIUM | 6.1 | 0.2% | Feb 18, 2022 | A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "... |
| CVE-2021-46372 | MEDIUM | 5.4 | 0.6% | Feb 18, 2022 | Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to... |
| CVE-2021-46108 | MEDIUM | 5.4 | 0.8% | Feb 18, 2022 | D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance config... |
| CVE-2021-3155 | MEDIUM | 5.5 | 0.3% | Feb 17, 2022 | snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. ... |
| CVE-2021-3753 | MEDIUM | 4.7 | 0.4% | Feb 16, 2022 | A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bo... |
| CVE-2021-4134 | MEDIUM | 4.9 | 1.4% | Feb 16, 2022 | The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameteriza... |
| CVE-2021-3557 | MEDIUM | 6.5 | 0.8% | Feb 16, 2022 | A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created Servi... |
| CVE-2021-22041 | MEDIUM | 6.7 | 0.6% | Feb 16, 2022 | VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor ... |
| CVE-2021-22040 | MEDIUM | 6.7 | 0.7% | Feb 16, 2022 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious acto... |
| CVE-2021-21966 | MEDIUM | 5.3 | 1.4% | Feb 16, 2022 | An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 S... |
| CVE-2021-46252 | MEDIUM | 6.5 | 0.5% | Feb 15, 2022 | A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attac... |
| CVE-2021-46251 | MEDIUM | 6.1 | 0.6% | Feb 15, 2022 | A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows at... |
| CVE-2021-46249 | MEDIUM | 6.5 | 0.6% | Feb 15, 2022 | An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856d... |
| CVE-2021-44960 | MEDIUM | 6.5 | 1.2% | Feb 15, 2022 | In SVGPP SVG++ library 1.3.0, the XMLDocument::getRoot function in the renderDocument function handled the XMLDocument o... |
| CVE-2021-46558 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to e... |
| CVE-2021-46557 | MEDIUM | 5.4 | 0.6% | Feb 15, 2022 | Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs. |
| CVE-2021-43948 | MEDIUM | 4.3 | 0.8% | Feb 15, 2022 | Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi... |
| CVE-2021-43941 | MEDIUM | 6.5 | 0.6% | Feb 15, 2022 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including... |
| CVE-2021-43953 | MEDIUM | 4.3 | 0.5% | Feb 15, 2022 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread C... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now