2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32626HIGH8.8Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts ex...
CVE-2021-23858HIGH7.5Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected...
CVE-2021-23857CRITICAL9.8Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the...
CVE-2021-23856MEDIUM6.1The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s c...
CVE-2021-23855HIGH7.5The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashi...
CVE-2021-41596MEDIUM5.3SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc...
CVE-2021-41595MEDIUM5.3SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc...
CVE-2021-41593HIGH8.6Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure.
CVE-2021-41592CRITICAL9.4Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.
CVE-2021-41591CRITICAL9.4ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure.
CVE-2021-41530HIGH7.5Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplif...
CVE-2021-41103HIGH7.8containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was fou...
CVE-2021-40683HIGH7.8In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquot...
CVE-2021-39900LOW2.7Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in o...
CVE-2021-39899MEDIUM4.2In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s passwor...
CVE-2021-39896LOW3.8In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonat...
CVE-2021-39885MEDIUM5.4A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions ...
CVE-2021-39883MEDIUM4.3Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from...
CVE-2021-39879LOW3.5Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's...
CVE-2021-39877MEDIUM5.5A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resour...
CVE-2021-39874MEDIUM4.3In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git command...
CVE-2021-39873MEDIUM4.3In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to tr...
CVE-2021-39871MEDIUM4.3In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import ...
CVE-2021-39868MEDIUM4.3In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project ...
CVE-2021-36850MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now