2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-38208 | MEDIUM | 5.5 | 0.5% | Aug 8, 2021 | net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NUL... |
| CVE-2021-38206 | MEDIUM | 5.5 | 0.3% | Aug 8, 2021 | The mac80211 subsystem in the Linux kernel before 5.12.13, when a device supporting only 5 GHz is used, allows attackers... |
| CVE-2021-38204 | MEDIUM | 6.8 | 0.3% | Aug 8, 2021 | drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial... |
| CVE-2021-38203 | MEDIUM | 5.5 | 0.4% | Aug 8, 2021 | btrfs in the Linux kernel before 5.13.4 allows attackers to cause a denial of service (deadlock) via processes that trig... |
| CVE-2021-38200 | MEDIUM | 5.5 | 0.3% | Aug 8, 2021 | arch/powerpc/perf/core-book3s.c in the Linux kernel before 5.12.13, on systems with perf_event_paranoid=-1 and no specif... |
| CVE-2021-38199 | MEDIUM | 6.5 | 1.2% | Aug 8, 2021 | fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of... |
| CVE-2021-38198 | MEDIUM | 5.5 | 0.5% | Aug 8, 2021 | arch/x86/kvm/mmu/paging_tmpl.h in the Linux kernel before 5.12.11 incorrectly computes the access permissions of a shado... |
| CVE-2021-38193 | MEDIUM | 6.1 | 0.7% | Aug 8, 2021 | An issue was discovered in the ammonia crate before 3.1.0 for Rust. XSS can occur because the parsing differences for HT... |
| CVE-2021-38191 | MEDIUM | 5.9 | 0.8% | Aug 8, 2021 | An issue was discovered in the tokio crate before 1.8.1 for Rust. Upon a JoinHandle::abort, a Task may be dropped in the... |
| CVE-2021-38186 | MEDIUM | 6.1 | 0.7% | Aug 8, 2021 | An issue was discovered in the comrak crate before 0.10.1 for Rust. It mishandles & characters, leading to XSS via &# HT... |
| CVE-2021-36221 | MEDIUM | 5.9 | 3.1% | Aug 8, 2021 | Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic ... |
| CVE-2021-38165 | MEDIUM | 5.3 | 4.5% | Aug 7, 2021 | Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext cr... |
| CVE-2021-38157 | MEDIUM | 6.1 | 1.1% | Aug 6, 2021 | LeoStream Connection Broker 9.x before 9.0.34.3 allows Unauthenticated Reflected XSS via the /index.pl user parameter. N... |
| CVE-2021-20598 | MEDIUM | 5.3 | 1.5% | Aug 6, 2021 | Overly Restrictive Account Lockout Mechanism vulnerability in Mitsubishi Electric MELSEC iQ-R series CPU modules (R08/16... |
| CVE-2021-36454 | MEDIUM | 5.4 | 0.6% | Aug 6, 2021 | Cross Site Scripting (XSS) vulnerability in Naviwebs Navigate Cms 2.9 via the navigate-quickse parameter to 1) backups\b... |
| CVE-2021-38136 | MEDIUM | 6.5 | 1.2% | Aug 6, 2021 | Corero SecureWatch Managed Services 9.7.2.0020 is affected by a Path Traversal vulnerability via the snap_file parameter... |
| CVE-2021-26999 | MEDIUM | 4.3 | 0.6% | Aug 6, 2021 | NetApp Cloud Manager versions prior to 3.9.9 log sensitive information when an Active Directory connection fails. The lo... |
| CVE-2021-26998 | MEDIUM | 4.3 | 0.6% | Aug 6, 2021 | NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users. Cu... |
| CVE-2021-37554 | MEDIUM | 4.3 | 0.9% | Aug 6, 2021 | In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions. |
| CVE-2021-37552 | MEDIUM | 5.4 | 0.6% | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.17925, stored XSS was possible. |
| CVE-2021-37551 | MEDIUM | 5.3 | 0.7% | Aug 6, 2021 | In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. |
| CVE-2021-37547 | MEDIUM | 5.3 | 0.7% | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.4, insufficient checks during file uploading were made. |
| CVE-2021-37546 | MEDIUM | 5.3 | 0.5% | Aug 6, 2021 | In JetBrains TeamCity before 2021.1, an insecure key generation mechanism for encrypted properties was used. |
| CVE-2021-37542 | MEDIUM | 6.1 | 0.6% | Aug 6, 2021 | In JetBrains TeamCity before 2020.2.3, XSS was possible. |
| CVE-2021-37541 | MEDIUM | 6.1 | 0.5% | Aug 6, 2021 | In JetBrains Hub before 2021.1.13402, HTML injection in the password reset email was possible. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now