2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20225MEDIUM6.7A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a hea...
CVE-2021-20076HIGH8.8Tenable.sc and Tenable.sc Core versions 5.13.0 through 5.17.0 were found to contain a vulnerability that could allow an ...
CVE-2021-3419Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. No...
CVE-2021-27215CRITICAL9.8An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. ...
CVE-2021-26813HIGH7.5markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacke...
CVE-2021-25252MEDIUM5.5Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vuln...
CVE-2021-25315HIGH7.8CWE - CWE-287: Improper Authentication vulnerability in SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows...
CVE-2021-23347MEDIUM4.8The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scri...
CVE-2021-27923HIGH7.5Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co...
CVE-2021-27922HIGH7.5Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co...
CVE-2021-27921HIGH7.5Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a co...
CVE-2021-2138MEDIUM4.6Vulnerability in the Oracle Cloud Infrastructure Data Science Notebook Sessions. Easily exploitable vulnerability allows...
CVE-2021-22863HIGH8.1An improper access control vulnerability was identified in the GitHub Enterprise Server GraphQL API that allowed authent...
CVE-2021-22862MEDIUM6.5An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user w...
CVE-2021-22861MEDIUM6.5An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of ...
CVE-2021-21353CRITICAL9Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker wa...
CVE-2021-21352CRITICAL9.1Anuko Time Tracker is an open source, web-based time tracking application written in PHP. In TimeTracker before version ...
CVE-2021-27078CRITICAL9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-27065HIGH7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26858HIGH7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26857HIGH7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26855CRITICAL9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26854MEDIUM6.6Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-26412CRITICAL9.1Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-21258MEDIUM5.4GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now