2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-22217MEDIUM6.5A denial of service vulnerability in all versions of GitLab CE/EE before 13.12.2, 13.11.5 or 13.10.5 allows an attacker ...
CVE-2021-22213MEDIUM6.5A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak...
CVE-2021-33571HIGH7.5In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_...
CVE-2021-33203MEDIUM4.9Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.a...
CVE-2021-32674HIGH8.8Zope is an open-source web application server. This advisory extends the previous advisory at https://github.com/zopefou...
CVE-2021-28293CRITICAL9.8Seceon aiSIEM before 6.3.2 (build 585) is prone to an unauthenticated account takeover vulnerability in the Forgot Passw...
CVE-2021-21559MEDIUM5.3Dell EMC NetWorker, versions 18.x, 19.1.x, 19.2.x 19.3.x, 19.4, and 19.4.0.1 contain an Improper Certificate Validation ...
CVE-2021-21558MEDIUM4.4Dell EMC NetWorker, 18.x, 19.1.x, 19.2.x 19.3.x, 19.4 and 19.4.0.1, contains an Information Disclosure vulnerability. A ...
CVE-2021-32673CRITICAL9.8reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg...
CVE-2021-32015MEDIUM6In Nuvoton NPCT75x TPM 1.2 firmware 7.4.0.0, a local authenticated malicious user with high privileges could potentially...
CVE-2021-22218LOW2.6All versions of GitLab CE/EE starting from 12.8 before 13.10.5, all versions starting from 13.11 before 13.11.5, and all...
CVE-2021-22215LOW2.7An information disclosure vulnerability in GitLab EE versions 13.11 and later allowed a project owner to leak informatio...
CVE-2021-34280HIGH7.8Polaris Office v9.103.83.44230 is affected by a Uninitialized Pointer Vulnerability in PolarisOffice.exe and EngineDLL.d...
CVE-2021-33190MEDIUM5.3In Apache APISIX Dashboard version 2.6, we changed the default value of listen host to 0.0.0.0 in order to facilitate us...
CVE-2021-33176HIGH7.5VerneMQ MQTT Broker versions prior to 1.12.0 are vulnerable to a denial of service attack as a result of excessive memor...
CVE-2021-33175HIGH7.5EMQ X Broker versions prior to 4.2.8 are vulnerable to a denial of service attack as a result of excessive memory consum...
CVE-2021-22214HIGH8.6When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE...
CVE-2021-30357MEDIUM5.3SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supp...
CVE-2021-22550HIGH7.8An attacker can modify the pointers in enclave memory to overwrite arbitrary memory addresses within the secure enclave....
CVE-2021-22549HIGH7.8An attacker can modify the address to point to trusted memory to overwrite arbitrary trusted memory. It is recommended t...
CVE-2021-22548HIGH7.8An attacker can change the pointer to untrusted memory to point to trusted memory region which causes copying trusted me...
CVE-2021-32106MEDIUM5.4In ICEcoder 8.0 allows, a reflected XSS vulnerability was identified in the multipe-results.php page due to insufficient...
CVE-2021-22212HIGH7.4ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters...
CVE-2021-3564MEDIUM5.5A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user a...
CVE-2021-26945MEDIUM5.5An integer overflow leading to a heap-buffer overflow was found in OpenEXR in versions before 3.0.1. An attacker could u...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now