2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-35492MEDIUM6.5Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources vi...
CVE-2021-41555MEDIUM6.1In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), XSS occurs in /archibus/dwr/call/plaincall/workflow.runWorkflo...
CVE-2021-39880MEDIUM6.5A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 b...
CVE-2021-39891MEDIUM4.9In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are ...
CVE-2021-39889MEDIUM4.3In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint m...
CVE-2021-39886MEDIUM4.3Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions startin...
CVE-2021-39870MEDIUM4.3In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enab...
CVE-2021-22264MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting fr...
CVE-2021-22262MEDIUM4.3Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before ...
CVE-2021-22261MEDIUM4.8A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14....
CVE-2021-22258MEDIUM4.3The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses
CVE-2021-22257MEDIUM5.3An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting fr...
CVE-2021-39894MEDIUM5.4In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be...
CVE-2021-39888MEDIUM4.3In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all v...
CVE-2021-39884MEDIUM4.3In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a pro...
CVE-2021-39882MEDIUM5.3In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information abo...
CVE-2021-39878MEDIUM5.4A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowe...
CVE-2021-39875MEDIUM5.3In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or pub...
CVE-2021-39872MEDIUM6.5In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired p...
CVE-2021-39869MEDIUM6.5In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
CVE-2021-39866MEDIUM5.4A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project acc...
CVE-2021-35506MEDIUM6.1Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor fo...
CVE-2021-39887MEDIUM5.4A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowe...
CVE-2021-37223MEDIUM6.5Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. ...
CVE-2021-35503MEDIUM6.1Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now