2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35492 | MEDIUM | 6.5 | 3.3% | Oct 5, 2021 | Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources vi... |
| CVE-2021-41555 | MEDIUM | 6.1 | 0.7% | Oct 5, 2021 | In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), XSS occurs in /archibus/dwr/call/plaincall/workflow.runWorkflo... |
| CVE-2021-39880 | MEDIUM | 6.5 | 1.3% | Oct 5, 2021 | A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 b... |
| CVE-2021-39891 | MEDIUM | 4.9 | 0.9% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are ... |
| CVE-2021-39889 | MEDIUM | 4.3 | 0.8% | Oct 5, 2021 | In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint m... |
| CVE-2021-39886 | MEDIUM | 4.3 | 0.5% | Oct 5, 2021 | Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions startin... |
| CVE-2021-39870 | MEDIUM | 4.3 | 0.9% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enab... |
| CVE-2021-22264 | MEDIUM | 6.5 | 1.0% | Oct 5, 2021 | An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting fr... |
| CVE-2021-22262 | MEDIUM | 4.3 | 0.7% | Oct 5, 2021 | Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before ... |
| CVE-2021-22261 | MEDIUM | 4.8 | 1.0% | Oct 5, 2021 | A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.... |
| CVE-2021-22258 | MEDIUM | 4.3 | 1.0% | Oct 5, 2021 | The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses |
| CVE-2021-22257 | MEDIUM | 5.3 | 0.9% | Oct 5, 2021 | An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting fr... |
| CVE-2021-39894 | MEDIUM | 5.4 | 0.6% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be... |
| CVE-2021-39888 | MEDIUM | 4.3 | 1.0% | Oct 5, 2021 | In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all v... |
| CVE-2021-39884 | MEDIUM | 4.3 | 1.0% | Oct 5, 2021 | In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a pro... |
| CVE-2021-39882 | MEDIUM | 5.3 | 0.6% | Oct 5, 2021 | In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information abo... |
| CVE-2021-39878 | MEDIUM | 5.4 | 0.8% | Oct 5, 2021 | A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowe... |
| CVE-2021-39875 | MEDIUM | 5.3 | 1.1% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or pub... |
| CVE-2021-39872 | MEDIUM | 6.5 | 1.0% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired p... |
| CVE-2021-39869 | MEDIUM | 6.5 | 1.2% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. |
| CVE-2021-39866 | MEDIUM | 5.4 | 1.0% | Oct 5, 2021 | A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project acc... |
| CVE-2021-35506 | MEDIUM | 6.1 | 0.7% | Oct 5, 2021 | Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor fo... |
| CVE-2021-39887 | MEDIUM | 5.4 | 0.8% | Oct 5, 2021 | A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowe... |
| CVE-2021-37223 | MEDIUM | 6.5 | 7.5% | Oct 5, 2021 | Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. ... |
| CVE-2021-35503 | MEDIUM | 6.1 | 0.7% | Oct 5, 2021 | Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now