2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32615 | CRITICAL | 9.8 | 2.1% | May 13, 2021 | Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection. |
| CVE-2021-31876 | MEDIUM | 6.5 | 1.6% | May 13, 2021 | Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes i... |
| CVE-2021-29510 | HIGH | 7.5 | 1.0% | May 13, 2021 | Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'i... |
| CVE-2021-29506 | MEDIUM | 6.5 | 1.4% | May 13, 2021 | GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a re... |
| CVE-2021-27413 | HIGH | 7.8 | 10.0% | May 13, 2021 | Omron CX-One Versions 4.60 and prior, including CX-Server Versions 5.0.29.0 and prior, are vulnerable to a stack-based b... |
| CVE-2021-23910 | CRITICAL | 9.8 | 1.7% | May 13, 2021 | An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. There is a... |
| CVE-2021-23909 | CRITICAL | 9.8 | 2.4% | May 13, 2021 | An issue was discovered in HERMES 2.1 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The SH2 MC... |
| CVE-2021-23908 | CRITICAL | 9.8 | 2.4% | May 13, 2021 | An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A t... |
| CVE-2021-23907 | CRITICAL | 9.8 | 2.4% | May 13, 2021 | An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. The... |
| CVE-2021-23906 | MEDIUM | 6.8 | 0.8% | May 13, 2021 | An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A M... |
| CVE-2021-32925 | MEDIUM | 6.5 | 1.9% | May 13, 2021 | admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities. |
| CVE-2021-22140 | HIGH | 7.5 | 1.3% | May 13, 2021 | Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the A... |
| CVE-2021-22139 | MEDIUM | 6.5 | 1.0% | May 13, 2021 | Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack o... |
| CVE-2021-22138 | LOW | 3.7 | 0.5% | May 13, 2021 | In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitor... |
| CVE-2021-22137 | MEDIUM | 5.3 | 1.1% | May 13, 2021 | In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Sec... |
| CVE-2021-22136 | LOW | 3.5 | 0.3% | May 13, 2021 | In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.sessio... |
| CVE-2021-22135 | MEDIUM | 5.3 | 1.2% | May 13, 2021 | Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch sugges... |
| CVE-2021-29623 | LOW | 3.3 | 1.1% | May 13, 2021 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2021-32921 | MEDIUM | 5.9 | 1.6% | May 13, 2021 | An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret... |
| CVE-2021-32920 | HIGH | 7.5 | 2.3% | May 13, 2021 | Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests. |
| CVE-2021-32919 | HIGH | 7.5 | 1.4% | May 13, 2021 | An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enab... |
| CVE-2021-32918 | HIGH | 7.5 | 2.1% | May 13, 2021 | An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-s... |
| CVE-2021-32917 | MEDIUM | 5.3 | 2.2% | May 13, 2021 | An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither o... |
| CVE-2021-21424 | MEDIUM | 5.3 | 1.7% | May 13, 2021 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumera... |
| CVE-2021-20535 | MEDIUM | 5.4 | 0.5% | May 13, 2021 | IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now