2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22053 | HIGH | 8.8 | 12.7% | Nov 19, 2021 | Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to exe... |
| CVE-2021-37592 | CRITICAL | 9.8 | 1.6% | Nov 19, 2021 | Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP stack that can send a c... |
| CVE-2021-3920 | MEDIUM | 5.4 | 1.3% | Nov 19, 2021 | grav-plugin-admin is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-41436 | HIGH | 7.5 | 4.6% | Nov 19, 2021 | An HTTP request smuggling in web application in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, ... |
| CVE-2021-41435 | CRITICAL | 9.8 | 6.0% | Nov 19, 2021 | A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-A... |
| CVE-2021-3973 | HIGH | 7.8 | 1.7% | Nov 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-3968 | HIGH | 8 | 2.1% | Nov 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
| CVE-2021-3963 | MEDIUM | 4.3 | 0.4% | Nov 19, 2021 | kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3961 | MEDIUM | 5.4 | 0.7% | Nov 19, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3957 | MEDIUM | 4.3 | 0.4% | Nov 19, 2021 | kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3950 | MEDIUM | 5.4 | 0.8% | Nov 19, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3976 | MEDIUM | 6.5 | 0.4% | Nov 19, 2021 | kimai2 is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3974 | HIGH | 7.8 | 1.3% | Nov 19, 2021 | vim is vulnerable to Use After Free |
| CVE-2021-41532 | MEDIUM | 5.3 | 2.3% | Nov 19, 2021 | In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any un... |
| CVE-2021-39236 | HIGH | 8.8 | 2.5% | Nov 19, 2021 | In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, imper... |
| CVE-2021-39235 | MEDIUM | 6.5 | 1.5% | Nov 19, 2021 | In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated u... |
| CVE-2021-39234 | MEDIUM | 6.8 | 1.4% | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific requ... |
| CVE-2021-39233 | CRITICAL | 9.1 | 2.3% | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authori... |
| CVE-2021-39232 | HIGH | 8.8 | 1.6% | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, certain admin related SCM commands can be executed by any authenticated users, ... |
| CVE-2021-39231 | CRITICAL | 9.1 | 2.3% | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, ... |
| CVE-2021-36372 | CRITICAL | 9.8 | 2.4% | Nov 19, 2021 | In Apache Ozone versions prior to 1.2.0, Initially generated block tokens are persisted to the metadata database and can... |
| CVE-2021-42338 | CRITICAL | 9.8 | 5.6% | Nov 19, 2021 | 4MOSAn GCB Doctor’s login page has improper validation of Cookie, which allows an unauthenticated remote attacker to byp... |
| CVE-2021-44033 | MEDIUM | 6.8 | 0.5% | Nov 19, 2021 | In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed. |
| CVE-2021-44026 | CRITICAL | 9.8 | 42.9% | Nov 19, 2021 | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params. |
| CVE-2021-44025 | MEDIUM | 6.1 | 1.0% | Nov 19, 2021 | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when disp... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now