2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39940 | MEDIUM | 6.5 | 1.5% | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions start... |
| CVE-2021-39939 | MEDIUM | 6.5 | 0.9% | Dec 13, 2021 | An uncontrolled resource consumption vulnerability in GitLab Runner affecting all versions starting from 13.7 before 14.... |
| CVE-2021-39938 | MEDIUM | 6.5 | 0.9% | Dec 13, 2021 | A vulnerable regular expression pattern in GitLab CE/EE since version 8.15 before 14.3.6, all versions starting from 14.... |
| CVE-2021-39936 | MEDIUM | 4.3 | 1.0% | Dec 13, 2021 | Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting f... |
| CVE-2021-39934 | MEDIUM | 4.3 | 0.9% | Dec 13, 2021 | Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions st... |
| CVE-2021-39933 | MEDIUM | 6.5 | 1.4% | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions star... |
| CVE-2021-39932 | MEDIUM | 4.3 | 0.9% | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions start... |
| CVE-2021-39931 | MEDIUM | 4.3 | 0.9% | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.11 before 14.3.6, all versions start... |
| CVE-2021-39930 | MEDIUM | 4.3 | 0.8% | Dec 13, 2021 | Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 1... |
| CVE-2021-39919 | MEDIUM | 4.4 | 0.3% | Dec 13, 2021 | In all versions of GitLab CE/EE starting version 14.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all ... |
| CVE-2021-39918 | MEDIUM | 4.3 | 0.7% | Dec 13, 2021 | Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from... |
| CVE-2021-39917 | MEDIUM | 6.5 | 1.3% | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 before 14.3.6, all versions start... |
| CVE-2021-39916 | MEDIUM | 4.3 | 0.8% | Dec 13, 2021 | Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the conf... |
| CVE-2021-39915 | MEDIUM | 5.3 | 1.1% | Dec 13, 2021 | Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all ... |
| CVE-2021-39910 | MEDIUM | 4.3 | 1.0% | Dec 13, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 14.3.6, all versions start... |
| CVE-2021-36169 | MEDIUM | 6 | 0.3% | Dec 13, 2021 | A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unaut... |
| CVE-2021-42549 | MEDIUM | 6.1 | 0.7% | Dec 13, 2021 | Insufficient Input Validation in the search functionality of Wordpress plugin Lets-Box prior to 1.15.3 allows unauthenti... |
| CVE-2021-42548 | MEDIUM | 6.1 | 0.7% | Dec 13, 2021 | Insufficient Input Validation in the search functionality of Wordpress plugin Share-one-Drive prior to 1.15.3 allows una... |
| CVE-2021-42547 | MEDIUM | 6.1 | 0.7% | Dec 13, 2021 | Insufficient Input Validation in the search functionality of Wordpress plugin Out-of-the-Box prior to 1.20.3 allows unau... |
| CVE-2021-42546 | MEDIUM | 6.1 | 0.7% | Dec 13, 2021 | Insufficient Input Validation in the search functionality of Wordpress plugin Use-Your-Drive prior to 1.18.3 allows unau... |
| CVE-2021-24972 | MEDIUM | 4.8 | 0.6% | Dec 13, 2021 | The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users... |
| CVE-2021-24955 | MEDIUM | 6.1 | 1.0% | Dec 13, 2021 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not escape the data para... |
| CVE-2021-24954 | MEDIUM | 6.1 | 1.0% | Dec 13, 2021 | The User Registration, Login Form, User Profile & Membership WordPress plugin before 3.2.3 does not sanitise and escape ... |
| CVE-2021-24932 | MEDIUM | 6.1 | 0.8% | Dec 13, 2021 | The Auto Featured Image (Auto Post Thumbnail) WordPress plugin before 3.9.3 does not sanitise and escape the post_id par... |
| CVE-2021-24925 | MEDIUM | 6.1 | 0.8% | Dec 13, 2021 | The Modern Events Calendar Lite WordPress plugin before 6.1.5 does not sanitise and escape the current_month_divider par... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now