2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-42380HIGH7.2A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte...
CVE-2021-42379HIGH7.2A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte...
CVE-2021-42378HIGH7.2A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafte...
CVE-2021-42377CRITICAL9.8An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when...
CVE-2021-42376MEDIUM5.5A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, ...
CVE-2021-42375MEDIUM5.5An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted ...
CVE-2021-42374MEDIUM5.3An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-...
CVE-2021-42373MEDIUM5.5A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no pag...
CVE-2021-41269CRITICAL9.8cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for th...
CVE-2021-41266CRITICAL9.8Minio console is a graphical user interface for the for MinIO operator. Minio itself is a multi-cloud object storage pro...
CVE-2021-41263HIGH8.8rails_multisite provides multi-db support for Rails applications. In affected versions this vulnerability impacts any Ra...
CVE-2021-41244HIGH7.2Grafana is an open-source platform for monitoring and observability. In affected versions when the fine-grained access c...
CVE-2021-39222MEDIUM6.1Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Talk application was vulnerable to a store...
CVE-2021-42580CRITICAL9.8Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm...
CVE-2021-41951MEDIUM6.1ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_ss...
CVE-2021-41950CRITICAL9.1A directory traversal issue in ResourceSpace 9.6 before 9.6 rev 18277 allows remote unauthenticated attackers to delete ...
CVE-2021-41765CRITICAL9.8A SQL injection issue in pages/edit_fields/9_ajax/add_keyword.php of ResourceSpace 9.5 and 9.6 < rev 18274 allows remote...
CVE-2021-38984HIGH7.5IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could ...
CVE-2021-38983HIGH7.5IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses weaker than expected cryptographic algorithms that could ...
CVE-2021-38982MEDIUM5.4IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allo...
CVE-2021-38981MEDIUM5.3IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information ...
CVE-2021-38979HIGH7.5IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 uses a one-way cryptographic hash against an input that should...
CVE-2021-38978MEDIUM5.9IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information,...
CVE-2021-38977MEDIUM4.3IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or s...
CVE-2021-38976MEDIUM5.5IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now