2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22877 | MEDIUM | 6.5 | 1.7% | Mar 3, 2021 | A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users exter... |
| CVE-2021-22188 | MEDIUM | 5.3 | 1.3% | Mar 3, 2021 | An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab we... |
| CVE-2021-22182 | MEDIUM | 5.4 | 1.0% | Mar 3, 2021 | An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS ... |
| CVE-2021-20441 | MEDIUM | 5.9 | 0.7% | Mar 3, 2021 | IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi... |
| CVE-2021-20225 | MEDIUM | 6.7 | 1.0% | Mar 3, 2021 | A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a hea... |
| CVE-2021-25252 | MEDIUM | 5.5 | 0.6% | Mar 3, 2021 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vuln... |
| CVE-2021-23347 | MEDIUM | 4.8 | 0.5% | Mar 3, 2021 | The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scri... |
| CVE-2021-2138 | MEDIUM | 4.6 | 0.4% | Mar 3, 2021 | Vulnerability in the Oracle Cloud Infrastructure Data Science Notebook Sessions. Easily exploitable vulnerability allows... |
| CVE-2021-22862 | MEDIUM | 6.5 | 0.8% | Mar 3, 2021 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user w... |
| CVE-2021-22861 | MEDIUM | 6.5 | 0.9% | Mar 3, 2021 | An improper access control vulnerability was identified in GitHub Enterprise Server that allowed authenticated users of ... |
| CVE-2021-26854 | MEDIUM | 6.6 | 19.6% | Mar 3, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability |
| CVE-2021-21258 | MEDIUM | 5.4 | 0.7% | Mar 2, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2021-21255 | MEDIUM | 5.7 | 0.9% | Mar 2, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2021-22296 | MEDIUM | 5.5 | 0.2% | Mar 2, 2021 | A component of HarmonyOS 2.0 has a DoS vulnerability. Local attackers may exploit this vulnerability to mount a file sys... |
| CVE-2021-22187 | MEDIUM | 4.3 | 1.0% | Mar 2, 2021 | An issue has been discovered in GitLab affecting all versions of Gitlab EE/CE before 13.6.7. A potential resource exhaus... |
| CVE-2021-3384 | MEDIUM | 5.3 | 1.0% | Mar 2, 2021 | A vulnerability in Stormshield Network Security could allow an attacker to trigger a protection related to ARP/NDP table... |
| CVE-2021-21514 | MEDIUM | 4.9 | 5.4% | Mar 2, 2021 | Dell EMC OpenManage Server Administrator (OMSA) versions 9.5 and prior contain a path traversal vulnerability. A remote ... |
| CVE-2021-27904 | MEDIUM | 5.5 | 0.3% | Mar 2, 2021 | An issue was discovered in app/Model/SharingGroupServer.php in MISP 2.4.139. In the implementation of Sharing Groups, th... |
| CVE-2021-27901 | MEDIUM | 6.8 | 0.1% | Mar 2, 2021 | An issue was discovered on LG mobile devices with Android OS 11 software. They mishandle fingerprint recognition because... |
| CVE-2021-21320 | MEDIUM | 4.3 | 0.9% | Mar 2, 2021 | matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0... |
| CVE-2021-27888 | MEDIUM | 6.1 | 0.6% | Mar 2, 2021 | ZendTo before 6.06-4 Beta allows XSS during the display of a drop-off in which a filename has unexpected characters. |
| CVE-2021-27731 | MEDIUM | 6.1 | 0.7% | Mar 2, 2021 | Accellion FTA 9_12_432 and earlier is affected by stored XSS via a crafted POST request to a user endpoint. The fixed ve... |
| CVE-2021-27884 | MEDIUM | 5.1 | 0.3% | Mar 1, 2021 | Weak JSON Web Token (JWT) signing secret generation in YMFE YApi through 1.9.2 allows recreation of other users' JWT tok... |
| CVE-2021-26702 | MEDIUM | 6.1 | 2.7% | Mar 1, 2021 | EPrints 3.4.2 exposes a reflected XSS opportunity in the dataset parameter to the cgi/dataset_dictionary URI. |
| CVE-2021-26475 | MEDIUM | 6.1 | 6.1% | Mar 1, 2021 | EPrints 3.4.2 exposes a reflected XSS opportunity in the via a cgi/cal URI. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now