2021 CVE Vulnerabilities

23,461 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3830MEDIUM5.4btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21742MEDIUM5.5There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter s...
CVE-2021-40655HIGH7.5An informtion disclosure issue exists in D-LINK-DIR-605 B2 Firmware Version : 2.01MT. An attacker can obtain a user name...
CVE-2021-40654MEDIUM6.5An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by fo...
CVE-2021-41504HIGH8An Elevated Privileges issue exists in D-Link DCS-5000L v1.05 and DCS-932L v2.17 and older. The use of the digest-authen...
CVE-2021-41503HIGH8DCS-5000L v1.05 and DCS-932L v2.17 and older are affecged by Incorrect Acess Control. The use of the basic authenticatio...
CVE-2021-39246MEDIUM6.1Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits...
CVE-2021-2464HIGH7.8Vulnerability in Oracle Linux (component: OSwatcher). Supported versions that are affected are 7 and 8. Easily exploitab...
CVE-2021-35313Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2021-22869CRITICAL9.8An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted ...
CVE-2021-22868MEDIUM4.3A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub...
CVE-2021-40310MEDIUM5.4OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.ph...
CVE-2021-40309HIGH8.8A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to ...
CVE-2021-28130HIGH7.8Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload w...
CVE-2021-41588HIGH8.1In Gradle Enterprise before 2021.1.3, a crafted request can trigger deserialization of arbitrary unsafe Java objects. Th...
CVE-2021-41587HIGH7.5In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially discover cred...
CVE-2021-41586HIGH7.5In Gradle Enterprise before 2021.1.3, an attacker with the ability to perform SSRF attacks can potentially reset the sys...
CVE-2021-40102CRITICAL9.1An issue was discovered in Concrete CMS through 8.5.5. Arbitrary File deletion can occur via PHAR deserialization in is_...
CVE-2021-40100MEDIUM5.4An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversatio...
CVE-2021-40099HIGH7.2An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code ex...
CVE-2021-36749MEDIUM6.5In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP In...
CVE-2021-41584HIGH7.5Gradle Enterprise before 2021.1.3 can allow unauthorized viewing of a response (information disclosure of possibly sensi...
CVE-2021-41583MEDIUM6.5vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows r...
CVE-2021-41581MEDIUM5.5x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buff...
CVE-2021-31923MEDIUM5.3Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now