2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3315 | MEDIUM | 5.4 | 0.5% | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible. |
| CVE-2021-31909 | CRITICAL | 9.8 | 3.2% | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, argument injection leading to remote code execution was possible. |
| CVE-2021-31908 | MEDIUM | 5.4 | 0.5% | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages. |
| CVE-2021-31907 | MEDIUM | 5.3 | 0.9% | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly. |
| CVE-2021-31906 | LOW | 2.7 | 0.6% | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, audit logs were not sufficient when an administrator uploaded a file. |
| CVE-2021-31905 | HIGH | 7.5 | 1.9% | May 11, 2021 | In JetBrains YouTrack before 2020.6.8801, information disclosure in an issue preview was possible. |
| CVE-2021-31904 | MEDIUM | 6.1 | 0.7% | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page. |
| CVE-2021-31903 | MEDIUM | 6.1 | 0.8% | May 11, 2021 | In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS. |
| CVE-2021-31902 | HIGH | 7.5 | 1.2% | May 11, 2021 | In JetBrains YouTrack before 2020.6.6600, access control during the exporting of issues was implemented improperly. |
| CVE-2021-31901 | HIGH | 7.5 | 0.9% | May 11, 2021 | In JetBrains Hub before 2021.1.13079, two-factor authentication wasn't enabled properly for the All Users group. |
| CVE-2021-31900 | MEDIUM | 5.3 | 0.7% | May 11, 2021 | In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host. |
| CVE-2021-31899 | HIGH | 8.8 | 1.3% | May 11, 2021 | In JetBrains Code With Me bundled to the compatible IDEs before version 2021.1, the client could execute code in read-on... |
| CVE-2021-30504 | HIGH | 7.5 | 2.3% | May 11, 2021 | In JetBrains IntelliJ IDEA before 2021.1, DoS was possible because of unbounded resource allocation. |
| CVE-2021-30006 | HIGH | 7.5 | 1.1% | May 11, 2021 | In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure. |
| CVE-2021-30005 | HIGH | 7.8 | 0.8% | May 11, 2021 | In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the ... |
| CVE-2021-29263 | HIGH | 7.8 | 0.5% | May 11, 2021 | In JetBrains IntelliJ IDEA 2020.3.3, local code execution was possible because of insufficient checks when getting the p... |
| CVE-2021-27733 | MEDIUM | 5.4 | 0.6% | May 11, 2021 | In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment. |
| CVE-2021-26310 | HIGH | 7.5 | 1.5% | May 11, 2021 | In the TeamCity IntelliJ plugin before 2020.2.2.85899, DoS was possible. |
| CVE-2021-26309 | LOW | 3.3 | 0.2% | May 11, 2021 | Information disclosure in the TeamCity plugin for IntelliJ before 2020.2.2.85899 was possible because a local temporary ... |
| CVE-2021-32544 | MEDIUM | 5.4 | 0.6% | May 11, 2021 | Special characters of IGT search function in igt+ are not filtered in specific fields, which allow remote authenticated ... |
| CVE-2021-30174 | MEDIUM | 5.4 | 0.6% | May 11, 2021 | RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filt... |
| CVE-2021-32563 | CRITICAL | 9.8 | 3.1% | May 11, 2021 | An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-l... |
| CVE-2021-32489 | MEDIUM | 4.4 | 0.9% | May 10, 2021 | An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not ... |
| CVE-2021-32399 | HIGH | 7 | 0.7% | May 10, 2021 | net/bluetooth/hci_request.c in the Linux kernel through 5.12.2 has a race condition for removal of the HCI controller. |
| CVE-2021-32053 | MEDIUM | 5.3 | 1.6% | May 10, 2021 | JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attac... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now