2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22258 | MEDIUM | 4.3 | 1.0% | Oct 5, 2021 | The project import/export feature in GitLab 8.9 and greater could be used to obtain otherwise private email addresses |
| CVE-2021-22257 | MEDIUM | 5.3 | 0.9% | Oct 5, 2021 | An issue has been discovered in GitLab affecting all versions starting from 14.0 before 14.0.9, all versions starting fr... |
| CVE-2021-39894 | MEDIUM | 5.4 | 0.6% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.0, a DNS rebinding vulnerability exists in Fogbugz importer which may be... |
| CVE-2021-39893 | HIGH | 7.5 | 1.1% | Oct 5, 2021 | A potential DOS vulnerability was discovered in GitLab starting with version 9.1 that allowed parsing files without auth... |
| CVE-2021-39888 | MEDIUM | 4.3 | 1.0% | Oct 5, 2021 | In all versions of GitLab EE starting from 13.10 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all v... |
| CVE-2021-39884 | MEDIUM | 4.3 | 1.0% | Oct 5, 2021 | In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a pro... |
| CVE-2021-39882 | MEDIUM | 5.3 | 0.6% | Oct 5, 2021 | In all versions of GitLab CE/EE, provided a user ID, anonymous users can use a few endpoints to retrieve information abo... |
| CVE-2021-39878 | MEDIUM | 5.4 | 0.8% | Oct 5, 2021 | A stored Reflected Cross-Site Scripting vulnerability in the Jira integration in GitLab version 13.0 up to 14.3.1 allowe... |
| CVE-2021-39875 | MEDIUM | 5.3 | 1.1% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 13.6, it is possible to see pending invitations of any public group or pub... |
| CVE-2021-39872 | MEDIUM | 6.5 | 1.0% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 14.1, an improper access control vulnerability allows users with expired p... |
| CVE-2021-39869 | MEDIUM | 6.5 | 1.2% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.9, project exports may expose trigger tokens configured on that project. |
| CVE-2021-39867 | HIGH | 8.1 | 0.9% | Oct 5, 2021 | In all versions of GitLab CE/EE since version 8.15, a DNS rebinding vulnerability in Gitea Importer may be exploited by ... |
| CVE-2021-39866 | MEDIUM | 5.4 | 1.0% | Oct 5, 2021 | A business logic error in the project deletion process in GitLab 13.6 and later allows persistent access via project acc... |
| CVE-2021-35506 | MEDIUM | 6.1 | 0.7% | Oct 5, 2021 | Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor fo... |
| CVE-2021-39887 | MEDIUM | 5.4 | 0.8% | Oct 5, 2021 | A stored Cross-Site Scripting vulnerability in the GitLab Flavored Markdown in GitLab CE/EE version 8.4 and above allowe... |
| CVE-2021-37223 | MEDIUM | 6.5 | 7.5% | Oct 5, 2021 | Nagios Enterprises NagiosXI <= 5.8.4 contains a Server-Side Request Forgery (SSRF) vulnerability in schedulereport.php. ... |
| CVE-2021-35505 | HIGH | 7.2 | 2.7% | Oct 5, 2021 | Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary... |
| CVE-2021-35504 | HIGH | 7.2 | 3.1% | Oct 5, 2021 | Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary... |
| CVE-2021-35503 | MEDIUM | 6.1 | 0.7% | Oct 5, 2021 | Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity... |
| CVE-2021-41773 | CRITICAL | 9.8 | 100.0% | Oct 5, 2021 | A flaw was found in a change made to path normalization in Apache HTTP Server 2.4.49. An attacker could use a path trave... |
| CVE-2021-41524 | HIGH | 7.5 | 25.0% | Oct 5, 2021 | While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing a... |
| CVE-2021-42008 | HIGH | 7.8 | 1.5% | Oct 5, 2021 | The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds wri... |
| CVE-2021-42006 | HIGH | 8.8 | 1.0% | Oct 4, 2021 | An out-of-bounds access in GffLine::GffLine in gff.cpp in GCLib 0.12.7 allows an attacker to cause a segmentation fault ... |
| CVE-2021-41123 | MEDIUM | 5.3 | 0.9% | Oct 4, 2021 | Survey Solutions is a survey management and data collection system. In affected versions the Headquarters application pu... |
| CVE-2021-41091 | MEDIUM | 6.3 | 2.7% | Oct 4, 2021 | Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker En... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now