2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25504 | MEDIUM | 4 | 0.2% | Nov 5, 2021 | Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information. |
| CVE-2021-25503 | MEDIUM | 6.7 | 0.1% | Nov 5, 2021 | Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execu... |
| CVE-2021-25502 | MEDIUM | 5.5 | 0.1% | Nov 5, 2021 | A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows ... |
| CVE-2021-25500 | MEDIUM | 4.4 | 0.1% | Nov 5, 2021 | A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE... |
| CVE-2021-39913 | MEDIUM | 6.7 | 0.3% | Nov 5, 2021 | Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versi... |
| CVE-2021-39912 | MEDIUM | 5.3 | 1.4% | Nov 5, 2021 | A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images w... |
| CVE-2021-39911 | MEDIUM | 4.3 | 0.7% | Nov 5, 2021 | An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting ... |
| CVE-2021-39909 | MEDIUM | 5.3 | 0.6% | Nov 5, 2021 | Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 b... |
| CVE-2021-39907 | MEDIUM | 5.3 | 1.4% | Nov 5, 2021 | A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from... |
| CVE-2021-39906 | MEDIUM | 6.1 | 60.7% | Nov 5, 2021 | Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaSc... |
| CVE-2021-39905 | MEDIUM | 4.3 | 0.9% | Nov 5, 2021 | An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic informati... |
| CVE-2021-39904 | MEDIUM | 4.3 | 0.8% | Nov 5, 2021 | An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14... |
| CVE-2021-39898 | MEDIUM | 5.3 | 1.2% | Nov 5, 2021 | In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may al... |
| CVE-2021-39897 | MEDIUM | 5.3 | 0.9% | Nov 5, 2021 | Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a proje... |
| CVE-2021-39895 | MEDIUM | 4.5 | 1.0% | Nov 5, 2021 | In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project ... |
| CVE-2021-22260 | MEDIUM | 5.4 | 0.9% | Nov 5, 2021 | A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.... |
| CVE-2021-39914 | MEDIUM | 4.3 | 1.0% | Nov 4, 2021 | A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause ... |
| CVE-2021-39903 | MEDIUM | 6.5 | 1.1% | Nov 4, 2021 | In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility le... |
| CVE-2021-39902 | MEDIUM | 4.3 | 0.8% | Nov 4, 2021 | Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the sev... |
| CVE-2021-43398 | MEDIUM | 5.3 | 1.9% | Nov 4, 2021 | Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation bet... |
| CVE-2021-41248 | MEDIUM | 4.7 | 1.0% | Nov 4, 2021 | GraphiQL is the reference implementation of this monorepo, GraphQL IDE, an official project under the GraphQL Foundation... |
| CVE-2021-41249 | MEDIUM | 4.7 | 1.2% | Nov 4, 2021 | GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-... |
| CVE-2021-43389 | MEDIUM | 5.5 | 0.7% | Nov 4, 2021 | An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_cap... |
| CVE-2021-43293 | MEDIUM | 4.3 | 0.8% | Nov 4, 2021 | Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform networ... |
| CVE-2021-40128 | MEDIUM | 5.3 | 1.0% | Nov 4, 2021 | A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacke... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now