2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20089HIGH8.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicio...
CVE-2021-20086HIGH8.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a m...
CVE-2021-20085HIGH8.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0...
CVE-2021-20083HIGH8.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object ...
CVE-2021-29469HIGH7.5Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to...
CVE-2021-22682HIGH7.8Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permis...
CVE-2021-22678HIGH7.8Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This c...
CVE-2021-22207MEDIUM6.5Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of servic...
CVE-2021-22205CRITICAL10An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati...
CVE-2021-22204HIGH7.8Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec...
CVE-2021-20088HIGH8.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows ...
CVE-2021-20087HIGH8.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows...
CVE-2021-20084HIGH8.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta a...
CVE-2021-31540HIGH7.1Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files i...
CVE-2021-31539MEDIUM5.5Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.pass...
CVE-2021-31410HIGH7.5Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote ...
CVE-2021-31408HIGH7.1Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6....
CVE-2021-22893CRITICAL10Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo...
CVE-2021-31407HIGH7.5Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9),...
CVE-2021-31406LOW2.5Non-constant-time comparison of CSRF tokens in endpoint request handler in com.vaadin:flow-server versions 3.0.0 through...
CVE-2021-31405HIGH7.5Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadi...
CVE-2021-31404LOW2.5Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0...
CVE-2021-31403LOW2.5Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7...
CVE-2021-26909MEDIUM5.3Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which...
CVE-2021-26908LOW3.3Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a lo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now