2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20669 | MEDIUM | 4.7 | 0.8% | Mar 10, 2021 | Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read a... |
| CVE-2021-20668 | LOW | 2.7 | 0.8% | Mar 10, 2021 | Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read a... |
| CVE-2021-20667 | MEDIUM | 5.4 | 0.7% | Mar 10, 2021 | Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI version... |
| CVE-2021-3310 | HIGH | 7.8 | 1.0% | Mar 10, 2021 | Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can ... |
| CVE-2021-28119 | CRITICAL | 9.8 | 3.6% | Mar 9, 2021 | Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC... |
| CVE-2021-28116 | MEDIUM | 5.3 | 13.0% | Mar 9, 2021 | Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bou... |
| CVE-2021-28115 | MEDIUM | 6.1 | 0.9% | Mar 9, 2021 | The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation. |
| CVE-2021-23273 | MEDIUM | 5.4 | 0.6% | Mar 9, 2021 | The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS... |
| CVE-2021-3411 | MEDIUM | 6.7 | 0.4% | Mar 9, 2021 | A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a... |
| CVE-2021-21300 | HIGH | 7.5 | 88.6% | Mar 9, 2021 | Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository th... |
| CVE-2021-20255 | MEDIUM | 5.5 | 0.4% | Mar 9, 2021 | A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This ... |
| CVE-2021-23353 | HIGH | 7.5 | 2.6% | Mar 9, 2021 | This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function. |
| CVE-2021-23352 | CRITICAL | 9.8 | 2.1% | Mar 9, 2021 | This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath optio... |
| CVE-2021-21295 | MEDIUM | 5.9 | 18.9% | Mar 9, 2021 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h... |
| CVE-2021-20246 | MEDIUM | 5.5 | 1.2% | Mar 9, 2021 | A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by Im... |
| CVE-2021-20245 | MEDIUM | 5.5 | 1.2% | Mar 9, 2021 | A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagic... |
| CVE-2021-20244 | MEDIUM | 5.5 | 1.2% | Mar 9, 2021 | A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed... |
| CVE-2021-21369 | MEDIUM | 6.5 | 1.5% | Mar 9, 2021 | Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 th... |
| CVE-2021-21190 | HIGH | 8.8 | 1.5% | Mar 9, 2021 | Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sens... |
| CVE-2021-21189 | MEDIUM | 4.3 | 1.5% | Mar 9, 2021 | Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass n... |
| CVE-2021-21188 | HIGH | 8.8 | 1.6% | Mar 9, 2021 | Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2021-21187 | MEDIUM | 4.3 | 1.5% | Mar 9, 2021 | Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perfo... |
| CVE-2021-21186 | MEDIUM | 4.3 | 1.1% | Mar 9, 2021 | Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who con... |
| CVE-2021-21185 | MEDIUM | 4.3 | 1.3% | Mar 9, 2021 | Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a... |
| CVE-2021-21184 | MEDIUM | 4.3 | 1.1% | Mar 9, 2021 | Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to lea... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now