2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-43182HIGH7.5In JetBrains Hub before 2021.1.13415, a DoS via user information is possible.
CVE-2021-43181MEDIUM6.1In JetBrains Hub before 2021.1.13690, stored XSS is possible.
CVE-2021-43180HIGH7.5In JetBrains Hub before 2021.1.13690, information disclosure via avatar metadata is possible.
CVE-2021-43203HIGH7.5In JetBrains Ktor before 1.6.4, nonce verification during the OAuth2 authentication process is implemented improperly.
CVE-2021-43201MEDIUM5.3In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
CVE-2021-43200CRITICAL9.8In JetBrains TeamCity before 2021.1.2, permission checks in the Agent Push functionality were insufficient.
CVE-2021-43199MEDIUM5.3In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.
CVE-2021-43198MEDIUM5.4In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
CVE-2021-43197MEDIUM6.1In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
CVE-2021-43196HIGH7.5In JetBrains TeamCity before 2021.1, information disclosure via the Docker Registry connection dialog is possible.
CVE-2021-43195MEDIUM5.3In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.
CVE-2021-43194MEDIUM5.3In JetBrains TeamCity before 2021.1.2, user enumeration was possible.
CVE-2021-43193CRITICAL9.8In JetBrains TeamCity before 2021.1.2, remote code execution via the agent push functionality is possible.
CVE-2021-43192MEDIUM5.3In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.
CVE-2021-43191MEDIUM5.3JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.
CVE-2021-43190MEDIUM5.3In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.
CVE-2021-43189HIGH7.3In JetBrains YouTrack Mobile before 2021.2, access token protection on Android is incomplete.
CVE-2021-43188HIGH7.3In JetBrains YouTrack Mobile before 2021.2, access token protection on iOS is incomplete.
CVE-2021-43187MEDIUM5.3In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.
CVE-2021-43186MEDIUM5.4JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
CVE-2021-43185CRITICAL9.8JetBrains YouTrack before 2021.3.23639 is vulnerable to Host header injection.
CVE-2021-43184MEDIUM5.4In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
CVE-2021-43183CRITICAL9.8In JetBrains Hub before 2021.1.13690, the authentication throttling mechanism could be bypassed.
CVE-2021-3641MEDIUM6.1Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoi...
CVE-2021-43519MEDIUM5.5Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now