2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-32615CRITICAL9.8Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
CVE-2021-31876MEDIUM6.5Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes i...
CVE-2021-29510HIGH7.5Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'i...
CVE-2021-29506MEDIUM6.5GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a re...
CVE-2021-27413HIGH7.8Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based b...
CVE-2021-23910CRITICAL9.8An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is a...
CVE-2021-23909CRITICAL9.8An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MC...
CVE-2021-23908CRITICAL9.8An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A t...
CVE-2021-23907CRITICAL9.8An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The...
CVE-2021-23906MEDIUM6.8An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A M...
CVE-2021-32925MEDIUM6.5admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
CVE-2021-22140HIGH7.5Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the A...
CVE-2021-22139MEDIUM6.5Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack o...
CVE-2021-22138LOW3.7In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitor...
CVE-2021-22137MEDIUM5.3In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Sec...
CVE-2021-22136LOW3.5In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.sessio...
CVE-2021-22135MEDIUM5.3Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch sugges...
CVE-2021-29623LOW3.3Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2021-32921MEDIUM5.9An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret...
CVE-2021-32920HIGH7.5Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
CVE-2021-32919HIGH7.5An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enab...
CVE-2021-32918HIGH7.5An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-s...
CVE-2021-32917MEDIUM5.3An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither o...
CVE-2021-21424MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumera...
CVE-2021-20535MEDIUM5.4IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now