2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22053HIGH8.8Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to exe...
CVE-2021-37592CRITICAL9.8Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a c...
CVE-2021-3920MEDIUM5.4grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41436HIGH7.5An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, ...
CVE-2021-41435CRITICAL9.8A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-A...
CVE-2021-3973HIGH7.8vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3968HIGH8vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-3963MEDIUM4.3kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3961MEDIUM5.4snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3957MEDIUM4.3kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3950MEDIUM5.4django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3976MEDIUM6.5kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3974HIGH7.8vim is vulnerable to Use After Free
CVE-2021-41532MEDIUM5.3In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any un...
CVE-2021-39236HIGH8.8In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, imper...
CVE-2021-39235MEDIUM6.5In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated u...
CVE-2021-39234MEDIUM6.8In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific requ...
CVE-2021-39233CRITICAL9.1In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authori...
CVE-2021-39232HIGH8.8In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, ...
CVE-2021-39231CRITICAL9.1In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, ...
CVE-2021-36372CRITICAL9.8In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can...
CVE-2021-42338CRITICAL9.84MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to byp...
CVE-2021-44033MEDIUM6.8In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.
CVE-2021-44026CRITICAL9.8Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
CVE-2021-44025MEDIUM6.1Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when disp...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now