2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20089 | HIGH | 8.8 | 1.6% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in purl 2.3.2 allows a malicio... |
| CVE-2021-20086 | HIGH | 8.8 | 6.1% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-bbq 1.2.1 allows a m... |
| CVE-2021-20085 | HIGH | 8.8 | 1.6% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in backbone-query-parameters 0... |
| CVE-2021-20083 | HIGH | 8.8 | 4.2% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-plugin-query-object ... |
| CVE-2021-29469 | HIGH | 7.5 | 1.7% | Apr 23, 2021 | Node-redis is a Node.js Redis client. Before version 3.1.1, when a client is in monitoring mode, the regex begin used to... |
| CVE-2021-22682 | HIGH | 7.8 | 0.2% | Apr 23, 2021 | Cscape (All versions prior to 9.90 SP4) is configured by default to be installed for all users, which allows full permis... |
| CVE-2021-22678 | HIGH | 7.8 | 1.0% | Apr 23, 2021 | Cscape (All versions prior to 9.90 SP4) lacks proper validation of user-supplied data when parsing project files. This c... |
| CVE-2021-22207 | MEDIUM | 6.5 | 2.0% | Apr 23, 2021 | Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of servic... |
| CVE-2021-22205 | CRITICAL | 10 | 99.7% | Apr 23, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati... |
| CVE-2021-22204 | HIGH | 7.8 | 100.0% | Apr 23, 2021 | Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec... |
| CVE-2021-20088 | HIGH | 8.8 | 1.4% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in mootools-more 1.6.0 allows ... |
| CVE-2021-20087 | HIGH | 8.8 | 2.1% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-deparam 0.5.1 allows... |
| CVE-2021-20084 | HIGH | 8.8 | 1.4% | Apr 23, 2021 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in jquery-sparkle 1.5.2-beta a... |
| CVE-2021-31540 | HIGH | 7.1 | 0.4% | Apr 23, 2021 | Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files i... |
| CVE-2021-31539 | MEDIUM | 5.5 | 0.3% | Apr 23, 2021 | Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.pass... |
| CVE-2021-31410 | HIGH | 7.5 | 1.7% | Apr 23, 2021 | Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote ... |
| CVE-2021-31408 | HIGH | 7.1 | 0.3% | Apr 23, 2021 | Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.... |
| CVE-2021-22893 | CRITICAL | 10 | 47.2% | Apr 23, 2021 | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windo... |
| CVE-2021-31407 | HIGH | 7.5 | 2.4% | Apr 23, 2021 | Vulnerability in OSGi integration in com.vaadin:flow-server versions 1.2.0 through 2.4.7 (Vaadin 12.0.0 through 14.4.9),... |
| CVE-2021-31406 | LOW | 2.5 | 0.2% | Apr 23, 2021 | Non-constant-time comparison of CSRF tokens in endpoint request handler in com.vaadin:flow-server versions 3.0.0 through... |
| CVE-2021-31405 | HIGH | 7.5 | 1.1% | Apr 23, 2021 | Unsafe validation RegEx in EmailField component in com.vaadin:vaadin-text-field-flow versions 2.0.4 through 2.3.2 (Vaadi... |
| CVE-2021-31404 | LOW | 2.5 | 0.2% | Apr 23, 2021 | Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:flow-server versions 1.0.0 through 1.0... |
| CVE-2021-31403 | LOW | 2.5 | 0.3% | Apr 23, 2021 | Non-constant-time comparison of CSRF tokens in UIDL request handler in com.vaadin:vaadin-server versions 7.0.0 through 7... |
| CVE-2021-26909 | MEDIUM | 5.3 | 0.7% | Apr 23, 2021 | Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which... |
| CVE-2021-26908 | LOW | 3.3 | 0.2% | Apr 23, 2021 | Automox Agent prior to version 31 logs potentially sensitive information in local log files, which could be used by a lo... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now