2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25767 | MEDIUM | 5.3 | 2.6% | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution. |
| CVE-2021-25766 | MEDIUM | 5.3 | 1.4% | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made. |
| CVE-2021-25763 | MEDIUM | 5.3 | 0.5% | Feb 3, 2021 | In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default. |
| CVE-2021-25762 | MEDIUM | 5.3 | 0.8% | Feb 3, 2021 | In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible. |
| CVE-2021-25761 | MEDIUM | 5.3 | 0.5% | Feb 3, 2021 | In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible. |
| CVE-2021-25760 | MEDIUM | 5.3 | 0.9% | Feb 3, 2021 | In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible. |
| CVE-2021-25759 | MEDIUM | 6.5 | 0.7% | Feb 3, 2021 | In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user. |
| CVE-2021-25757 | MEDIUM | 6.1 | 0.6% | Feb 3, 2021 | In JetBrains Hub before 2020.1.12629, an open redirect was possible. |
| CVE-2021-25756 | MEDIUM | 5.3 | 1.3% | Feb 3, 2021 | In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS. |
| CVE-2021-0365 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In display driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of... |
| CVE-2021-0364 | MEDIUM | 6.7 | 0.3% | Feb 3, 2021 | In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escala... |
| CVE-2021-0363 | MEDIUM | 6.7 | 0.3% | Feb 3, 2021 | In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalatio... |
| CVE-2021-0362 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In aee, there is a possible memory corruption due to a stack buffer overflow. This could lead to local escalation of pri... |
| CVE-2021-0361 | MEDIUM | 6.7 | 0.1% | Feb 3, 2021 | In kisd, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of... |
| CVE-2021-0360 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In netdiag, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalatio... |
| CVE-2021-0359 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2021-0358 | MEDIUM | 6.7 | 0.3% | Feb 3, 2021 | In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation ... |
| CVE-2021-0357 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2021-0356 | MEDIUM | 6.7 | 0.3% | Feb 3, 2021 | In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation ... |
| CVE-2021-0355 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In kisd, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of priv... |
| CVE-2021-0354 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi... |
| CVE-2021-0353 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In kisd, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of pri... |
| CVE-2021-0352 | MEDIUM | 4.4 | 0.1% | Feb 3, 2021 | In RT regmap driver, there is a possible memory corruption due to type confusion. This could lead to local denial of ser... |
| CVE-2021-21043 | MEDIUM | 6.1 | 3.3% | Feb 2, 2021 | ACS Commons version 4.9.2 (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in version-com... |
| CVE-2021-3395 | MEDIUM | 5.4 | 0.8% | Feb 2, 2021 | A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary f... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now