2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26042Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2021-26041Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was n...
CVE-2021-44839MEDIUM6.5An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the accoun...
CVE-2021-44838MEDIUM4.3An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating ...
CVE-2021-44836MEDIUM4.3An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it i...
CVE-2021-44840LOW2.7An issue was discovered in Delta RM 1.2. Using an privileged account, it is possible to edit, create, and delete risk la...
CVE-2021-46013CRITICAL9.8An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can ...
CVE-2021-46012Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA
CVE-2021-46005MEDIUM5.4Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter...
CVE-2021-34406MEDIUM4.7NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointe...
CVE-2021-34405MEDIUM5.5NVIDIA Linux distributions contain a vulnerability in TrustZone’s TEE_Malloc function, where an unchecked return value c...
CVE-2021-34404HIGH7.6Android images for T210 provided by NVIDIA contain a vulnerability in BROM, where failure to limit access to AHB-DMA whe...
CVE-2021-34403HIGH7.8NVIDIA Linux distributions contain a vulnerability in nvmap ioctl, which allows any user with a local account to exploit...
CVE-2021-34402MEDIUM6.7NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to ...
CVE-2021-34401HIGH7.8NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER, where imprope...
CVE-2021-4083HIGH7A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in...
CVE-2021-4074MEDIUM5.4The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter fou...
CVE-2021-43353HIGH8.8The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the...
CVE-2021-41809MEDIUM4.3SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making qu...
CVE-2021-41808LOW2.3In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log ...
CVE-2021-41807CRITICAL9.8Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of u...
CVE-2021-39946MEDIUM5.4Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowe...
CVE-2021-39942MEDIUM6.5A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions ...
CVE-2021-39927MEDIUM4.3Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and ...
CVE-2021-39892MEDIUM4.3In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now