2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39905 | MEDIUM | 4.3 | 0.9% | Nov 5, 2021 | An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic informati... |
| CVE-2021-39904 | MEDIUM | 4.3 | 0.8% | Nov 5, 2021 | An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14... |
| CVE-2021-39901 | LOW | 2.7 | 0.9% | Nov 5, 2021 | In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visitin... |
| CVE-2021-39898 | MEDIUM | 5.3 | 1.2% | Nov 5, 2021 | In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may al... |
| CVE-2021-39897 | MEDIUM | 5.3 | 0.9% | Nov 5, 2021 | Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a proje... |
| CVE-2021-39895 | MEDIUM | 4.5 | 1.0% | Nov 5, 2021 | In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project ... |
| CVE-2021-22260 | MEDIUM | 5.4 | 0.9% | Nov 5, 2021 | A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.... |
| CVE-2021-43400 | CRITICAL | 9.1 | 1.5% | Nov 4, 2021 | An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-... |
| CVE-2021-39914 | MEDIUM | 4.3 | 1.0% | Nov 4, 2021 | A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause ... |
| CVE-2021-39903 | MEDIUM | 6.5 | 1.1% | Nov 4, 2021 | In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility le... |
| CVE-2021-39902 | MEDIUM | 4.3 | 0.8% | Nov 4, 2021 | Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the sev... |
| CVE-2021-43398 | MEDIUM | 5.3 | 1.9% | Nov 4, 2021 | Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation bet... |
| CVE-2021-42057 | HIGH | 7.8 | 1.2% | Nov 4, 2021 | Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which... |
| CVE-2021-41248 | MEDIUM | 4.7 | 1.0% | Nov 4, 2021 | GraphiQL is the reference implementation of this monorepo, GraphQL IDE, an official project under the GraphQL Foundation... |
| CVE-2021-3896 | — | — | — | Nov 4, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43389. Reason: This candidate is a reservation d... |
| CVE-2021-43396 | HIGH | 7.5 | 2.9% | Nov 4, 2021 | In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spuriou... |
| CVE-2021-41249 | MEDIUM | 4.7 | 1.2% | Nov 4, 2021 | GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-... |
| CVE-2021-43389 | MEDIUM | 5.5 | 0.7% | Nov 4, 2021 | An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_cap... |
| CVE-2021-43293 | MEDIUM | 4.3 | 0.8% | Nov 4, 2021 | Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform networ... |
| CVE-2021-43281 | HIGH | 7.2 | 1.3% | Nov 4, 2021 | MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's S... |
| CVE-2021-41247 | HIGH | 7.5 | 0.8% | Nov 4, 2021 | JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple Jupyt... |
| CVE-2021-21698 | HIGH | 7.5 | 2.1% | Nov 4, 2021 | Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file ... |
| CVE-2021-21697 | CRITICAL | 9.1 | 1.6% | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build director... |
| CVE-2021-21696 | CRITICAL | 9.8 | 2.3% | Nov 4, 2021 | Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not limit agent read/write access to the libs/ directory inside ... |
| CVE-2021-21695 | HIGH | 8.8 | 2.1% | Nov 4, 2021 | FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Je... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now