2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20669MEDIUM4.7Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read a...
CVE-2021-20668LOW2.7Path traversal vulnerability in GROWI versions v4.2.2 and earlier allows an attacker with administrator rights to read a...
CVE-2021-20667MEDIUM5.4Stored cross-site scripting vulnerability due to inadequate CSP (Content Security Policy) configuration in GROWI version...
CVE-2021-3310HIGH7.8Western Digital My Cloud OS 5 devices before 5.10.122 mishandle Symbolic Link Following on SMB and AFP shares. This can ...
CVE-2021-28119CRITICAL9.8Twinkle Tray (aka twinkle-tray) through 1.13.3 allows remote command execution. A remote attacker may send a crafted IPC...
CVE-2021-28116MEDIUM5.3Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bou...
CVE-2021-28115MEDIUM6.1The OUGC Feedback plugin before 1.8.23 for MyBB allows XSS via the comment field of feedback during an edit operation.
CVE-2021-23273MEDIUM5.4The Spotfire client component of TIBCO Software Inc.'s TIBCO Spotfire Analyst, TIBCO Spotfire Analytics Platform for AWS...
CVE-2021-3411MEDIUM6.7A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a...
CVE-2021-21300HIGH7.5Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository th...
CVE-2021-20255MEDIUM5.5A stack overflow via an infinite recursion vulnerability was found in the eepro100 i8255x device emulator of QEMU. This ...
CVE-2021-23353HIGH7.5This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
CVE-2021-23352CRITICAL9.8This affects the package madge before 4.0.1. It is possible to specify a custom Graphviz path via the graphVizPath optio...
CVE-2021-21295MEDIUM5.9Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h...
CVE-2021-20246MEDIUM5.5A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by Im...
CVE-2021-20245MEDIUM5.5A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagic...
CVE-2021-20244MEDIUM5.5A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed...
CVE-2021-21369MEDIUM6.5Hyperledger Besu is an open-source, MainNet compatible, Ethereum client written in Java. In Besu before version 1.5.1 th...
CVE-2021-21190HIGH8.8Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sens...
CVE-2021-21189MEDIUM4.3Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass n...
CVE-2021-21188HIGH8.8Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap cor...
CVE-2021-21187MEDIUM4.3Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perfo...
CVE-2021-21186MEDIUM4.3Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who con...
CVE-2021-21185MEDIUM4.3Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a...
CVE-2021-21184MEDIUM4.3Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to lea...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now