2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41123 | MEDIUM | 5.3 | 0.9% | Oct 4, 2021 | Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application pu... |
| CVE-2021-41091 | MEDIUM | 6.3 | 2.7% | Oct 4, 2021 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En... |
| CVE-2021-41089 | MEDIUM | 6.3 | 0.3% | Oct 4, 2021 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En... |
| CVE-2021-41094 | MEDIUM | 4.6 | 0.2% | Oct 4, 2021 | Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by si... |
| CVE-2021-39347 | MEDIUM | 4.3 | 0.6% | Oct 4, 2021 | The Stripe for WooCommerce WordPress plugin is missing a capability check on the save() function found in the ~/includes... |
| CVE-2021-38400 | MEDIUM | 6.8 | 0.1% | Oct 4, 2021 | An attacker with physical access to Boston Scientific Zoom Latitude Model 3120 can remove the hard disk drive or create ... |
| CVE-2021-38398 | MEDIUM | 6.8 | 0.4% | Oct 4, 2021 | The affected device uses off-the-shelf software components that contain unpatched vulnerabilities. A malicious attacker ... |
| CVE-2021-38396 | MEDIUM | 6.8 | 0.2% | Oct 4, 2021 | The programmer installation utility does not perform a cryptographic authenticity or integrity checks of the software on... |
| CVE-2021-38394 | MEDIUM | 6.4 | 0.2% | Oct 4, 2021 | An attacker with physical access to the device can extract the binary that checks for the hardware key and reverse engin... |
| CVE-2021-32672 | MEDIUM | 4.3 | 1.7% | Oct 4, 2021 | Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send mal... |
| CVE-2021-23856 | MEDIUM | 6.1 | 0.6% | Oct 4, 2021 | The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s c... |
| CVE-2021-41596 | MEDIUM | 5.3 | 1.8% | Oct 4, 2021 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc... |
| CVE-2021-41595 | MEDIUM | 5.3 | 1.8% | Oct 4, 2021 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc... |
| CVE-2021-39899 | MEDIUM | 4.2 | 0.2% | Oct 4, 2021 | In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s passwor... |
| CVE-2021-39885 | MEDIUM | 5.4 | 1.0% | Oct 4, 2021 | A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions ... |
| CVE-2021-39883 | MEDIUM | 4.3 | 0.7% | Oct 4, 2021 | Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from... |
| CVE-2021-39877 | MEDIUM | 5.5 | 1.0% | Oct 4, 2021 | A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resour... |
| CVE-2021-39874 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git command... |
| CVE-2021-39873 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to tr... |
| CVE-2021-39871 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import ... |
| CVE-2021-39868 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project ... |
| CVE-2021-36850 | MEDIUM | 4.3 | 0.4% | Oct 4, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions ... |
| CVE-2021-22259 | MEDIUM | 6.5 | 1.0% | Oct 4, 2021 | A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in depend... |
| CVE-2021-25964 | MEDIUM | 5.4 | 0.5% | Oct 4, 2021 | In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access... |
| CVE-2021-41867 | MEDIUM | 5.3 | 1.7% | Oct 4, 2021 | An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now