2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22258MEDIUM4.3The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses
CVE-2021-22257MEDIUM5.3An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting fr...
CVE-2021-39894MEDIUM5.4In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be...
CVE-2021-39893HIGH7.5A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without auth...
CVE-2021-39888MEDIUM4.3In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all v...
CVE-2021-39884MEDIUM4.3In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a pro...
CVE-2021-39882MEDIUM5.3In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information abo...
CVE-2021-39878MEDIUM5.4A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowe...
CVE-2021-39875MEDIUM5.3In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or pub...
CVE-2021-39872MEDIUM6.5In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired p...
CVE-2021-39869MEDIUM6.5In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project.
CVE-2021-39867HIGH8.1In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by ...
CVE-2021-39866MEDIUM5.4A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project acc...
CVE-2021-35506MEDIUM6.1Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor fo...
CVE-2021-39887MEDIUM5.4A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowe...
CVE-2021-37223MEDIUM6.5Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. ...
CVE-2021-35505HIGH7.2Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary...
CVE-2021-35504HIGH7.2Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary...
CVE-2021-35503MEDIUM6.1Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity...
CVE-2021-41773CRITICAL9.8A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path trave...
CVE-2021-41524HIGH7.5While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing a...
CVE-2021-42008HIGH7.8The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds wri...
CVE-2021-42006HIGH8.8An out-of-bounds access in GffLine::GffLine in gff.cpp in GCLib 0.12.7 allows an attacker to cause a segmentation fault ...
CVE-2021-41123MEDIUM5.3Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application pu...
CVE-2021-41091MEDIUM6.3Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now