2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-39885MEDIUM5.4A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions ...
CVE-2021-39883MEDIUM4.3Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from...
CVE-2021-39879LOW3.5Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's...
CVE-2021-39877MEDIUM5.5A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resour...
CVE-2021-39874MEDIUM4.3In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git command...
CVE-2021-39873MEDIUM4.3In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to tr...
CVE-2021-39871MEDIUM4.3In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import ...
CVE-2021-39868MEDIUM4.3In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project ...
CVE-2021-36850MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions ...
CVE-2021-35296CRITICAL9.8An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via m...
CVE-2021-22259MEDIUM6.5A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in depend...
CVE-2021-25964MEDIUM5.4In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access...
CVE-2021-41868CRITICAL9.8OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --...
CVE-2021-41867MEDIUM5.3An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve...
CVE-2021-39486MEDIUM5.4A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, pass...
CVE-2021-38823CRITICAL9.8The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not ...
CVE-2021-38822MEDIUM5.4A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that ...
CVE-2021-37777HIGH7.5Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visib...
CVE-2021-37333CRITICAL9.8Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.or...
CVE-2021-37331MEDIUM5.3Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uplo...
CVE-2021-37330MEDIUM5.4Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile...
CVE-2021-36051HIGH7.8XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arb...
CVE-2021-41511CRITICAL9.8The username and password field of login in Lodging Reservation Management System V1 can give access to any user by usin...
CVE-2021-41878MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable...
CVE-2021-24687MEDIUM4.8The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting th...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now