2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-38208MEDIUM5.5net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NUL...
CVE-2021-38206MEDIUM5.5The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers...
CVE-2021-38204MEDIUM6.8drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial...
CVE-2021-38203MEDIUM5.5btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trig...
CVE-2021-38200MEDIUM5.5arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13, on systems with perf_event_paranoid=-1 and no specif...
CVE-2021-38199MEDIUM6.5fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of...
CVE-2021-38198MEDIUM5.5arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shado...
CVE-2021-38193MEDIUM6.1An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HT...
CVE-2021-38191MEDIUM5.9An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the...
CVE-2021-38186MEDIUM6.1An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HT...
CVE-2021-36221MEDIUM5.9Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic ...
CVE-2021-38165MEDIUM5.3Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext cr...
CVE-2021-38157MEDIUM6.1LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. N...
CVE-2021-20598MEDIUM5.3Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16...
CVE-2021-36454MEDIUM5.4Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\b...
CVE-2021-38136MEDIUM6.5Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter...
CVE-2021-26999MEDIUM4.3NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The lo...
CVE-2021-26998MEDIUM4.3NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Cu...
CVE-2021-37554MEDIUM4.3In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
CVE-2021-37552MEDIUM5.4In JetBrains YouTrack before 2021.2.17925, stored XSS was possible.
CVE-2021-37551MEDIUM5.3In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
CVE-2021-37547MEDIUM5.3In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made.
CVE-2021-37546MEDIUM5.3In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used.
CVE-2021-37542MEDIUM6.1In JetBrains TeamCity before 2020.2.3, XSS was possible.
CVE-2021-37541MEDIUM6.1In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now