2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3625 | CRITICAL | 9.8 | 2.3% | Oct 5, 2021 | Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For mo... |
| CVE-2021-3581 | HIGH | 8.8 | 0.3% | Oct 5, 2021 | Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Len... |
| CVE-2021-3510 | HIGH | 7.5 | 0.9% | Oct 5, 2021 | Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access ... |
| CVE-2021-3436 | MEDIUM | 6.5 | 0.9% | Oct 5, 2021 | BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known... |
| CVE-2021-3319 | CRITICAL | 9.8 | 0.9% | Oct 5, 2021 | DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses. Zephyr versions >= > v2.4.0 contain NULL Poi... |
| CVE-2021-41116 | CRITICAL | 9.8 | 2.9% | Oct 5, 2021 | Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer ... |
| CVE-2021-41114 | MEDIUM | 5.3 | 1.2% | Oct 5, 2021 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ... |
| CVE-2021-41113 | HIGH | 8.8 | 0.6% | Oct 5, 2021 | TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ... |
| CVE-2021-39226 | HIGH | 7.3 | 99.9% | Oct 5, 2021 | Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are ... |
| CVE-2021-35497 | HIGH | 7.5 | 0.4% | Oct 5, 2021 | The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO Active... |
| CVE-2021-41553 | CRITICAL | 9.8 | 1.2% | Oct 5, 2021 | In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session t... |
| CVE-2021-41286 | HIGH | 7.8 | 0.2% | Oct 5, 2021 | Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the appli... |
| CVE-2021-35492 | MEDIUM | 6.5 | 3.3% | Oct 5, 2021 | Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources vi... |
| CVE-2021-35491 | HIGH | 8.1 | 0.9% | Oct 5, 2021 | A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to... |
| CVE-2021-41555 | MEDIUM | 6.1 | 0.7% | Oct 5, 2021 | In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), XSS occurs in /archibus/dwr/call/plaincall/workflow.runWorkflo... |
| CVE-2021-41554 | HIGH | 8.8 | 0.8% | Oct 5, 2021 | ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functio... |
| CVE-2021-39880 | MEDIUM | 6.5 | 1.3% | Oct 5, 2021 | A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 b... |
| CVE-2021-39891 | MEDIUM | 4.9 | 0.9% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are ... |
| CVE-2021-39889 | MEDIUM | 4.3 | 0.8% | Oct 5, 2021 | In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint m... |
| CVE-2021-39886 | MEDIUM | 4.3 | 0.5% | Oct 5, 2021 | Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions startin... |
| CVE-2021-39881 | LOW | 3.5 | 0.8% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client appli... |
| CVE-2021-39870 | MEDIUM | 4.3 | 0.9% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enab... |
| CVE-2021-22264 | MEDIUM | 6.5 | 1.0% | Oct 5, 2021 | An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting fr... |
| CVE-2021-22262 | MEDIUM | 4.3 | 0.7% | Oct 5, 2021 | Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before ... |
| CVE-2021-22261 | MEDIUM | 4.8 | 1.0% | Oct 5, 2021 | A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14.... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now