2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-31865 | MEDIUM | 5.3 | 1.1% | Apr 28, 2021 | Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensi... |
| CVE-2021-31864 | MEDIUM | 5.3 | 1.2% | Apr 28, 2021 | Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permissi... |
| CVE-2021-31863 | HIGH | 7.5 | 1.7% | Apr 28, 2021 | Insufficient input validation in the Git repository integration of Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x b... |
| CVE-2021-31779 | MEDIUM | 6.4 | 0.5% | Apr 28, 2021 | The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account. |
| CVE-2021-31778 | MEDIUM | 5.4 | 0.5% | Apr 28, 2021 | The media2click (aka 2 Clicks for External Media) extension 1.x before 1.3.3 for TYPO3 allows XSS by a backend user acco... |
| CVE-2021-31777 | MEDIUM | 4.9 | 1.4% | Apr 28, 2021 | The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allo... |
| CVE-2021-27933 | MEDIUM | 6.1 | 26.6% | Apr 28, 2021 | pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field. |
| CVE-2021-31856 | CRITICAL | 9.8 | 75.4% | Apr 28, 2021 | A SQL Injection vulnerability in the REST API in Layer5 Meshery 0.5.2 allows an attacker to execute arbitrary SQL comman... |
| CVE-2021-31815 | LOW | 3.3 | 0.1% | Apr 28, 2021 | GAEN (aka Google/Apple Exposure Notifications) through 2021-04-27 on Android allows attackers to obtain sensitive inform... |
| CVE-2021-3512 | HIGH | 8.8 | 0.9% | Apr 28, 2021 | Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH ... |
| CVE-2021-3511 | MEDIUM | 4.3 | 0.5% | Apr 28, 2021 | Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmwar... |
| CVE-2021-20716 | CRITICAL | 9.8 | 3.2% | Apr 28, 2021 | Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 ... |
| CVE-2021-29476 | CRITICAL | 9.8 | 2.1% | Apr 27, 2021 | Requests is a HTTP library written in PHP. Requests mishandles deserialization in FilteredIterator. The issue has been p... |
| CVE-2021-29472 | HIGH | 8.8 | 4.8% | Apr 27, 2021 | Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source d... |
| CVE-2021-29442 | HIGH | 7.5 | 64.7% | Apr 27, 2021 | Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver... |
| CVE-2021-29441 | CRITICAL | 9.8 | 74.8% | Apr 27, 2021 | Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before ver... |
| CVE-2021-30128 | CRITICAL | 9.8 | 81.1% | Apr 27, 2021 | Apache OFBiz has unsafe deserialization prior to 17.12.07 version |
| CVE-2021-29460 | MEDIUM | 5.4 | 3.2% | Apr 27, 2021 | Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful... |
| CVE-2021-29200 | CRITICAL | 9.8 | 55.4% | Apr 27, 2021 | Apache OFBiz has unsafe deserialization prior to 17.12.07 version An unauthenticated user can perform an RCE attack |
| CVE-2021-21429 | LOW | 3.3 | 0.3% | Apr 27, 2021 | OpenAPI Generator allows generation of API client libraries, server stubs, documentation and configuration automatically... |
| CVE-2021-21365 | MEDIUM | 5.4 | 0.9% | Apr 27, 2021 | Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnera... |
| CVE-2021-30638 | HIGH | 7.5 | 6.6% | Apr 27, 2021 | Information Exposure vulnerability in context asset handling of Apache Tapestry allows an attacker to download files ins... |
| CVE-2021-29667 | HIGH | 7.8 | 1.2% | Apr 27, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is potentially vulnerable to CSV Injection. A remote ... |
| CVE-2021-29666 | MEDIUM | 5.4 | 0.5% | Apr 27, 2021 | IBM Spectrum Scale 5.0.0 through 5.0.5.6 and 5.1.0 through 5.1.0.2 is vulnerable to cross-site scripting. This vulnerabi... |
| CVE-2021-20550 | MEDIUM | 5.4 | 0.5% | Apr 27, 2021 | IBM Content Navigator 3.0.CD is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now