2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-22172MEDIUM4.3Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccess...
CVE-2021-21333MEDIUM6.1Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-25372MEDIUM6.7An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
CVE-2021-25371MEDIUM6.7A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
CVE-2021-25370MEDIUM4.4An incorrect implementation handling file descriptor in dpu driver prior to SMR Mar-2021 Release 1 results in memory cor...
CVE-2021-25369MEDIUM5.5An improper access control vulnerability in sec_log file prior to SMR MAR-2021 Release 1 exposes sensitive kernel inform...
CVE-2021-22886MEDIUM6.1Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdo...
CVE-2021-20289MEDIUM5.3A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are retu...
CVE-2021-20285MEDIUM6.6A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SE...
CVE-2021-20284MEDIUM5.5A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_s...
CVE-2021-20197MEDIUM6.3There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar,...
CVE-2021-1629MEDIUM6.1Tableau Server fails to validate certain URLs that are embedded in emails sent to Tableau Server users.
CVE-2021-3109MEDIUM4.8The custom menu item options page in SolarWinds Orion Platform before 2020.2.5 allows Reverse Tabnabbing in the context ...
CVE-2021-3275MEDIUM6.1Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless A...
CVE-2021-23890MEDIUM6.5Information leak vulnerability in the Agent Handler of McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ...
CVE-2021-23889MEDIUM4.8Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 allows ePO administrator...
CVE-2021-23888MEDIUM6.3Unvalidated client-side URL redirect vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10 Update 10 could ca...
CVE-2021-20683MEDIUM5.4Improper neutralization of JavaScript input in the blog article editing function of baserCMS versions prior to 4.4.5 all...
CVE-2021-20681MEDIUM5.4Improper neutralization of JavaScript input in the page editing function of baserCMS versions prior to 4.4.5 allows remo...
CVE-2021-28247MEDIUM5.4CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticat...
CVE-2021-3153MEDIUM6.5HashiCorp Terraform Enterprise up to v202102-2 failed to enforce an organization-level setting that required users withi...
CVE-2021-3027MEDIUM6.5app/views_mod/user/user.py in LibrIT PaSSHport through 2.5 is affected by LDAP Injection. There is an information leak t...
CVE-2021-29095MEDIUM6.8Multiple uninitialized pointer vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and e...
CVE-2021-29094MEDIUM6.8Multiple buffer overflow vulnerabilities when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier...
CVE-2021-29093MEDIUM6.8A use-after-free vulnerability when parsing a specially crafted file in Esri ArcGIS Server 10.8.1 (and earlier) allows a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now