2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-31865MEDIUM5.3Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensi...
CVE-2021-31864MEDIUM5.3Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permissi...
CVE-2021-31863HIGH7.5Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x b...
CVE-2021-31779MEDIUM6.4The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
CVE-2021-31778MEDIUM5.4The media2click (aka 2 Clicks for External Media) extension 1.x before 1.3.3 for TYPO3 allows XSS by a backend user acco...
CVE-2021-31777MEDIUM4.9The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allo...
CVE-2021-27933MEDIUM6.1pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.
CVE-2021-31856CRITICAL9.8A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL comman...
CVE-2021-31815LOW3.3GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android allows attackers to obtain sensitive inform...
CVE-2021-3512HIGH8.8Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH ...
CVE-2021-3511MEDIUM4.3Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmwar...
CVE-2021-20716CRITICAL9.8Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 ...
CVE-2021-29476CRITICAL9.8Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been p...
CVE-2021-29472HIGH8.8Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source d...
CVE-2021-29442HIGH7.5Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver...
CVE-2021-29441CRITICAL9.8Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver...
CVE-2021-30128CRITICAL9.8Apache OFBiz has unsafe deserialization prior to 17.12.07 version
CVE-2021-29460MEDIUM5.4Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful...
CVE-2021-29200CRITICAL9.8Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack
CVE-2021-21429LOW3.3OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically...
CVE-2021-21365MEDIUM5.4Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnera...
CVE-2021-30638HIGH7.5Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files ins...
CVE-2021-29667HIGH7.8IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote ...
CVE-2021-29666MEDIUM5.4IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerabi...
CVE-2021-20550MEDIUM5.4IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now