2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-25504MEDIUM4Intent redirection vulnerability in Group Sharing prior to 10.8.03.2 allows attacker to access contact information.
CVE-2021-25503MEDIUM6.7Improper input validation vulnerability in HDCP prior to SMR Nov-2021 Release 1 allows attackers to arbitrary code execu...
CVE-2021-25502MEDIUM5.5A vulnerability of storing sensitive information insecurely in Property Settings prior to SMR Nov-2021 Release 1 allows ...
CVE-2021-25500MEDIUM4.4A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to overwrite TZASC allowing TEE...
CVE-2021-39913MEDIUM6.7Accidental logging of system root password in the migration log in all versions of GitLab CE/EE before 14.2.6, all versi...
CVE-2021-39912MEDIUM5.3A potential DoS vulnerability was discovered in GitLab CE/EE starting with version 13.7. Using a malformed TIFF images w...
CVE-2021-39911MEDIUM4.3An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting ...
CVE-2021-39909MEDIUM5.3Lack of email address ownership verification in the CODEOWNERS feature in all versions of GitLab EE starting from 11.3 b...
CVE-2021-39907MEDIUM5.3A potential DOS vulnerability was discovered in GitLab CE/EE starting with version 13.7. The stripping of EXIF data from...
CVE-2021-39906MEDIUM6.1Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaSc...
CVE-2021-39905MEDIUM4.3An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic informati...
CVE-2021-39904MEDIUM4.3An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14...
CVE-2021-39898MEDIUM5.3In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may al...
CVE-2021-39897MEDIUM5.3Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a proje...
CVE-2021-39895MEDIUM4.5In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project ...
CVE-2021-22260MEDIUM5.4A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13....
CVE-2021-39914MEDIUM4.3A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause ...
CVE-2021-39903MEDIUM6.5In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility le...
CVE-2021-39902MEDIUM4.3Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the sev...
CVE-2021-43398MEDIUM5.3Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation bet...
CVE-2021-41248MEDIUM4.7GraphiQL is the reference implementation of this monorepo, GraphQL IDE, an official project under the GraphQL Foundation...
CVE-2021-41249MEDIUM4.7GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-...
CVE-2021-43389MEDIUM5.5An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_cap...
CVE-2021-43293MEDIUM4.3Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform networ...
CVE-2021-40128MEDIUM5.3A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacke...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now