2021 CVE Vulnerabilities
23,452 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32626 | HIGH | 8.8 | 15.1% | Oct 4, 2021 | Redis is an open source, in-memory database that persists on disk. In affected versions specially crafted Lua scripts ex... |
| CVE-2021-23858 | HIGH | 7.5 | 1.2% | Oct 4, 2021 | Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected... |
| CVE-2021-23857 | CRITICAL | 9.8 | 1.2% | Oct 4, 2021 | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the... |
| CVE-2021-23856 | MEDIUM | 6.1 | 0.6% | Oct 4, 2021 | The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s c... |
| CVE-2021-23855 | HIGH | 7.5 | 0.6% | Oct 4, 2021 | The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashi... |
| CVE-2021-41596 | MEDIUM | 5.3 | 1.8% | Oct 4, 2021 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc... |
| CVE-2021-41595 | MEDIUM | 5.3 | 1.8% | Oct 4, 2021 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially inc... |
| CVE-2021-41593 | HIGH | 8.6 | 1.9% | Oct 4, 2021 | Lightning Labs lnd before 0.13.3-beta allows loss of funds because of dust HTLC exposure. |
| CVE-2021-41592 | CRITICAL | 9.4 | 1.5% | Oct 4, 2021 | Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure. |
| CVE-2021-41591 | CRITICAL | 9.4 | 1.7% | Oct 4, 2021 | ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure. |
| CVE-2021-41530 | HIGH | 7.5 | 0.9% | Oct 4, 2021 | Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplif... |
| CVE-2021-41103 | HIGH | 7.8 | 0.5% | Oct 4, 2021 | containerd is an open source container runtime with an emphasis on simplicity, robustness and portability. A bug was fou... |
| CVE-2021-40683 | HIGH | 7.8 | 0.4% | Oct 4, 2021 | In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquot... |
| CVE-2021-39900 | LOW | 2.7 | 0.6% | Oct 4, 2021 | Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in o... |
| CVE-2021-39899 | MEDIUM | 4.2 | 0.2% | Oct 4, 2021 | In all versions of GitLab CE/EE, an attacker with physical access to a user’s machine may brute force the user’s passwor... |
| CVE-2021-39896 | LOW | 3.8 | 0.6% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 8.0, when an admin uses the impersonate feature twice and stops impersonat... |
| CVE-2021-39885 | MEDIUM | 5.4 | 1.0% | Oct 4, 2021 | A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions ... |
| CVE-2021-39883 | MEDIUM | 4.3 | 0.7% | Oct 4, 2021 | Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from... |
| CVE-2021-39879 | LOW | 3.5 | 0.4% | Oct 4, 2021 | Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's... |
| CVE-2021-39877 | MEDIUM | 5.5 | 1.0% | Oct 4, 2021 | A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resour... |
| CVE-2021-39874 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git command... |
| CVE-2021-39873 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to tr... |
| CVE-2021-39871 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import ... |
| CVE-2021-39868 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project ... |
| CVE-2021-36850 | MEDIUM | 4.3 | 0.4% | Oct 4, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now