2021 CVE Vulnerabilities
23,461 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-39885 | MEDIUM | 5.4 | 1.0% | Oct 4, 2021 | A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions ... |
| CVE-2021-39883 | MEDIUM | 4.3 | 0.7% | Oct 4, 2021 | Improper authorization checks in all versions of GitLab EE starting from 13.11 before 14.1.7, all versions starting from... |
| CVE-2021-39879 | LOW | 3.5 | 0.4% | Oct 4, 2021 | Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's... |
| CVE-2021-39877 | MEDIUM | 5.5 | 1.0% | Oct 4, 2021 | A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resour... |
| CVE-2021-39874 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 11.0, the requirement to enforce 2FA is not honored when using git command... |
| CVE-2021-39873 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE, there exists a content spoofing vulnerability which may be leveraged by attackers to tr... |
| CVE-2021-39871 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 13.0, an instance that has the setting to disable Bitbucket Server import ... |
| CVE-2021-39868 | MEDIUM | 4.3 | 0.9% | Oct 4, 2021 | In all versions of GitLab CE/EE since version 8.12, an authenticated low-privileged malicious user may create a project ... |
| CVE-2021-36850 | MEDIUM | 4.3 | 0.4% | Oct 4, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in WordPress Media File Renamer – Auto & Manual Rename plugin (versions ... |
| CVE-2021-35296 | CRITICAL | 9.8 | 1.9% | Oct 4, 2021 | An issue in the administrator authentication panel of PTCL HG150-Ub v3.0 allows attackers to bypass authentication via m... |
| CVE-2021-22259 | MEDIUM | 6.5 | 1.0% | Oct 4, 2021 | A potential DOS vulnerability was discovered in GitLab EE starting with version 12.6 due to lack of pagination in depend... |
| CVE-2021-25964 | MEDIUM | 5.4 | 0.5% | Oct 4, 2021 | In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access... |
| CVE-2021-41868 | CRITICAL | 9.8 | 2.3% | Oct 4, 2021 | OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to upload files on a non-public node when using the --... |
| CVE-2021-41867 | MEDIUM | 5.3 | 1.7% | Oct 4, 2021 | An information disclosure vulnerability in OnionShare 2.3 before 2.4 allows remote unauthenticated attackers to retrieve... |
| CVE-2021-39486 | MEDIUM | 5.4 | 0.6% | Oct 4, 2021 | A Stored XSS via Malicious File Upload exists in Gila CMS version 2.2.0. An attacker can use this to steal cookies, pass... |
| CVE-2021-38823 | CRITICAL | 9.8 | 1.5% | Oct 4, 2021 | The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not ... |
| CVE-2021-38822 | MEDIUM | 5.4 | 0.7% | Oct 4, 2021 | A Stored Cross Site Scripting vulnerability via Malicious File Upload exists in multiple pages of IceHrm 30.0.0.OS that ... |
| CVE-2021-37777 | HIGH | 7.5 | 1.6% | Oct 4, 2021 | Gila CMS 2.2.0 is vulnerable to Insecure Direct Object Reference (IDOR). Thumbnails uploaded by one site owner are visib... |
| CVE-2021-37333 | CRITICAL | 9.8 | 1.4% | Oct 4, 2021 | Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.or... |
| CVE-2021-37331 | MEDIUM | 5.3 | 0.9% | Oct 4, 2021 | Laravel Booking System Booking Core 2.0 is vulnerable to Incorrect Access Control. On the Verifications page, after uplo... |
| CVE-2021-37330 | MEDIUM | 5.4 | 0.6% | Oct 4, 2021 | Laravel Booking System Booking Core 2.0 is vulnerable to Cross Site Scripting (XSS). The Avatar upload in the My Profile... |
| CVE-2021-36051 | HIGH | 7.8 | 5.4% | Oct 4, 2021 | XMP Toolkit SDK version 2020.1 (and earlier) is affected by a buffer overflow vulnerability potentially resulting in arb... |
| CVE-2021-41511 | CRITICAL | 9.8 | 3.2% | Oct 4, 2021 | The username and password field of login in Lodging Reservation Management System V1 can give access to any user by usin... |
| CVE-2021-41878 | MEDIUM | 6.1 | 9.9% | Oct 4, 2021 | A reflected cross-site scripting (XSS) vulnerability exists in the i-Panel Administration System Version 2.0 that enable... |
| CVE-2021-24687 | MEDIUM | 4.8 | 0.6% | Oct 4, 2021 | The Modern Events Calendar Lite WordPress plugin before 5.22.2 does not escape some of its settings before outputting th... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now