2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3625CRITICAL9.8Buffer overflow in Zephyr USB DFU DNLOAD. Zephyr versions >= v2.5.0 contain Heap-based Buffer Overflow (CWE-122). For mo...
CVE-2021-3581HIGH8.8Buffer Access with Incorrect Length Value in zephyr. Zephyr versions >= >=2.5.0 contain Buffer Access with Incorrect Len...
CVE-2021-3510HIGH7.5Zephyr JSON decoder incorrectly decodes array of array. Zephyr versions >= >1.14.0, >= >2.5.0 contain Attempt to Access ...
CVE-2021-3436MEDIUM6.5BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known...
CVE-2021-3319CRITICAL9.8DOS: Incorrect 802154 Frame Validation for Omitted Source / Dest Addresses. Zephyr versions >= > v2.4.0 contain NULL Poi...
CVE-2021-41116CRITICAL9.8Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer ...
CVE-2021-41114MEDIUM5.3TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ...
CVE-2021-41113HIGH8.8TYPO3 is an open source PHP based web content management system released under the GNU GPL. It has been discovered that ...
CVE-2021-39226HIGH7.3Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are ...
CVE-2021-35497HIGH7.5The FTL Server (tibftlserver) and Docker images containing tibftlserver components of TIBCO Software Inc.'s TIBCO Active...
CVE-2021-41553CRITICAL9.8In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), the Web Application in /archibus/login.axvw assign a session t...
CVE-2021-41286HIGH7.8Omikron MultiCash Desktop 4.00.008.SP5 relies on a client-side authentication mechanism. When a user logs into the appli...
CVE-2021-35492MEDIUM6.5Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources vi...
CVE-2021-35491HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to...
CVE-2021-41555MEDIUM6.1In ARCHIBUS Web Central 21.3.3.815 (a version from 2014), XSS occurs in /archibus/dwr/call/plaincall/workflow.runWorkflo...
CVE-2021-41554HIGH8.8ARCHIBUS Web Central 21.3.3.815 (a version from 2014) does not properly validate requests for access to data and functio...
CVE-2021-39880MEDIUM6.5A Denial Of Service vulnerability in the apollo_upload_server Ruby gem in GitLab CE/EE all versions starting from 11.9 b...
CVE-2021-39891MEDIUM4.9In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are ...
CVE-2021-39889MEDIUM4.3In all versions of GitLab EE since version 14.1, due to an insecure direct object reference vulnerability, an endpoint m...
CVE-2021-39886MEDIUM4.3Permissions rules were not applied while issues were moved between projects of the same group in GitLab versions startin...
CVE-2021-39881LOW3.5In all versions of GitLab CE/EE since version 7.7, the application may let a malicious user create an OAuth client appli...
CVE-2021-39870MEDIUM4.3In all versions of GitLab CE/EE since version 11.11, an instance that has the setting to disable Repo by URL import enab...
CVE-2021-22264MEDIUM6.5An issue has been discovered in GitLab affecting all versions starting from 13.8 before 14.0.9, all versions starting fr...
CVE-2021-22262MEDIUM4.3Missing access control in all GitLab versions starting from 13.12 before 14.0.9, all versions starting from 14.1 before ...
CVE-2021-22261MEDIUM4.8A stored Cross-Site Scripting vulnerability in the Jira integration in all GitLab versions starting from 13.9 before 14....

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now