2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41123MEDIUM5.3Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application pu...
CVE-2021-41091MEDIUM6.3Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En...
CVE-2021-41089MEDIUM6.3Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En...
CVE-2021-41094MEDIUM4.6Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by si...
CVE-2021-39347MEDIUM4.3The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes...
CVE-2021-38400MEDIUM6.8An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create ...
CVE-2021-38398MEDIUM6.8The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker ...
CVE-2021-38396MEDIUM6.8The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on...
CVE-2021-38394MEDIUM6.4An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engin...
CVE-2021-32672MEDIUM4.3Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send mal...
CVE-2021-23856MEDIUM6.1The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s c...
CVE-2021-41596MEDIUM5.3SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc...
CVE-2021-41595MEDIUM5.3SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc...
CVE-2021-39899MEDIUM4.2In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s passwor...
CVE-2021-39885MEDIUM5.4A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions ...
CVE-2021-39883MEDIUM4.3Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from...
CVE-2021-39877MEDIUM5.5A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resour...
CVE-2021-39874MEDIUM4.3In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git command...
CVE-2021-39873MEDIUM4.3In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to tr...
CVE-2021-39871MEDIUM4.3In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import ...
CVE-2021-39868MEDIUM4.3In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project ...
CVE-2021-36850MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions ...
CVE-2021-22259MEDIUM6.5A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in depend...
CVE-2021-25964MEDIUM5.4In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access...
CVE-2021-41867MEDIUM5.3An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now