2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3315MEDIUM5.4In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
CVE-2021-31909CRITICAL9.8In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible.
CVE-2021-31908MEDIUM5.4In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
CVE-2021-31907MEDIUM5.3In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.
CVE-2021-31906LOW2.7In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file.
CVE-2021-31905HIGH7.5In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible.
CVE-2021-31904MEDIUM6.1In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
CVE-2021-31903MEDIUM6.1In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
CVE-2021-31902HIGH7.5In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly.
CVE-2021-31901HIGH7.5In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group.
CVE-2021-31900MEDIUM5.3In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.
CVE-2021-31899HIGH8.8In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-on...
CVE-2021-30504HIGH7.5In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation.
CVE-2021-30006HIGH7.5In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
CVE-2021-30005HIGH7.8In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the ...
CVE-2021-29263HIGH7.8In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the p...
CVE-2021-27733MEDIUM5.4In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
CVE-2021-26310HIGH7.5In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible.
CVE-2021-26309LOW3.3Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary ...
CVE-2021-32544MEDIUM5.4Special characters of IGT search function in igt+ are not filtered in specific fields, which allow remote authenticated ...
CVE-2021-30174MEDIUM5.4RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filt...
CVE-2021-32563CRITICAL9.8An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-l...
CVE-2021-32489MEDIUM4.4An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not ...
CVE-2021-32399HIGH7net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller.
CVE-2021-32053MEDIUM5.3JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attac...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now