2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39905MEDIUM4.3An information disclosure vulnerability in the GitLab CE/EE API since version 8.9.6 allows a user to see basic informati...
CVE-2021-39904MEDIUM4.3An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14...
CVE-2021-39901LOW2.7In all versions of GitLab CE/EE since version 11.10, an admin of a group can see the SCIM token of that group by visitin...
CVE-2021-39898MEDIUM5.3In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may al...
CVE-2021-39897MEDIUM5.3Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a proje...
CVE-2021-39895MEDIUM4.5In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project ...
CVE-2021-22260MEDIUM5.4A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13....
CVE-2021-43400CRITICAL9.1An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-...
CVE-2021-39914MEDIUM4.3A regular expression denial of service issue in GitLab versions 8.13 to 14.2.5, 14.3.0 to 14.3.3 and 14.4.0 could cause ...
CVE-2021-39903MEDIUM6.5In all versions of GitLab CE/EE since version 13.0, a privileged user, through an API call, can change the visibility le...
CVE-2021-39902MEDIUM4.3Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the sev...
CVE-2021-43398MEDIUM5.3Crypto++ (aka Cryptopp) 8.6.0 and earlier contains a timing leakage in MakePublicKey(). There is a clear correlation bet...
CVE-2021-42057HIGH7.8Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which...
CVE-2021-41248MEDIUM4.7GraphiQL is the reference implementation of this monorepo, GraphQL IDE, an official project under the GraphQL Foundation...
CVE-2021-3896Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2021-43389. Reason: This candidate is a reservation d...
CVE-2021-43396HIGH7.5In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spuriou...
CVE-2021-41249MEDIUM4.7GraphQL Playground is a GraphQL IDE for development of graphQL focused applications. All versions of graphql-playground-...
CVE-2021-43389MEDIUM5.5An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_cap...
CVE-2021-43293MEDIUM4.3Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform networ...
CVE-2021-43281HIGH7.2MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's S...
CVE-2021-41247HIGH7.5JupyterHub is an open source multi-user server for Jupyter notebooks. In affected versions users who have multiple Jupyt...
CVE-2021-21698HIGH7.5Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file ...
CVE-2021-21697CRITICAL9.1Jenkins 2.318 and earlier, LTS 2.303.2 and earlier allows any agent to read and write the contents of any build director...
CVE-2021-21696CRITICAL9.8Jenkins 2.318 and earlier, LTS 2.303.2 and earlier does not limit agent read/write access to the libs/ directory inside ...
CVE-2021-21695HIGH8.8FilePath#listFiles lists files outside directories that agents are allowed to access when following symbolic links in Je...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now