2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20180MEDIUM5.5A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by th...
CVE-2021-0957HIGH7.8In NotificationStackScrollLayout of NotificationStackScrollLayout.java, there is a possible way to bypass Factory Reset ...
CVE-2021-45787MEDIUM5.4There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted...
CVE-2021-45786CRITICAL9.8In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privile...
CVE-2021-42552MEDIUM6.1Cross-site Scripting (XSS) vulnerability in ArchivistaBox webclient allows an attacker to craft a malicious link, execut...
CVE-2021-46705MEDIUM4.4A Insecure Temporary File vulnerability in grub-once of grub2 in SUSE Linux Enterprise Server 15 SP4, openSUSE Factory a...
CVE-2021-45852MEDIUM5.3An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patie...
CVE-2021-45851HIGH7.5A Server-Side Request Forgery (SSRF) attack in FUXA 1.1.3 can be carried out leading to the obtaining of sensitive infor...
CVE-2021-43958CRITICAL9.8Various rest resources in Fisheye and Crucible before version 4.8.9 allowed remote attackers to brute force user login c...
CVE-2021-43957HIGH7.5Affected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct ...
CVE-2021-43956MEDIUM6.1The jQuery deserialize library in Fisheye and Crucible before version 4.8.9 allowed remote attackers to to inject arbitr...
CVE-2021-43955MEDIUM4.3The /rest-service-fecru/server-v1 resource in Fisheye and Crucible before version 4.8.9 allowed authenticated remote att...
CVE-2021-29134MEDIUM5.3The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.
CVE-2021-45848HIGH7.5Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to cras...
CVE-2021-45010HIGH8.8A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7...
CVE-2021-43305HIGH8.8Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that...
CVE-2021-43304HIGH8.8Heap buffer overflow in Clickhouse's LZ4 compression codec when parsing a malicious query. There is no verification that...
CVE-2021-42391MEDIUM6.5Divide-by-zero in Clickhouse's Gorilla compression codec when parsing a malicious query. The first byte of the compresse...
CVE-2021-42390MEDIUM6.5Divide-by-zero in Clickhouse's DeltaDouble compression codec when parsing a malicious query. The first byte of the compr...
CVE-2021-42389MEDIUM6.5Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed ...
CVE-2021-42388HIGH8.1Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decomp...
CVE-2021-42387HIGH8.1Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decomp...
CVE-2021-39055MEDIUM5.4IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to cross-site scripting. This vulnerability all...
CVE-2021-39051MEDIUM6.5IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by impro...
CVE-2021-38971MEDIUM4.9IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an authorized user to byp...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now