2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20334 | HIGH | 7.8 | 0.2% | Apr 6, 2021 | A malicious 3rd party with local access to the Windows machine where MongoDB Compass is installed can execute arbitrary ... |
| CVE-2021-30146 | MEDIUM | 5.4 | 0.9% | Apr 6, 2021 | Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality." |
| CVE-2021-30140 | MEDIUM | 5.4 | 1.4% | Apr 6, 2021 | LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrat... |
| CVE-2021-29424 | HIGH | 7.5 | 2.0% | Apr 6, 2021 | The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of... |
| CVE-2021-29136 | MEDIUM | 5.5 | 0.3% | Apr 6, 2021 | Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that... |
| CVE-2021-26833 | MEDIUM | 5.9 | 1.0% | Apr 6, 2021 | Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attac... |
| CVE-2021-30130 | HIGH | 7.5 | 1.1% | Apr 6, 2021 | phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification. |
| CVE-2021-28658 | MEDIUM | 5.3 | 3.9% | Apr 6, 2021 | In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via up... |
| CVE-2021-28142 | HIGH | 8.8 | 5.8% | Apr 6, 2021 | CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete." |
| CVE-2021-30046 | MEDIUM | 6.5 | 1.0% | Apr 6, 2021 | VIGRA Computer Vision Library Version-1-11-1 contains a segmentation fault vulnerability in the impex.hxx read_image_ban... |
| CVE-2021-30045 | CRITICAL | 9.1 | 1.8% | Apr 6, 2021 | SerenityOS 2021-03-27 contains a buffer overflow vulnerability in the EndOfCentralDirectory::read() function. |
| CVE-2021-28874 | HIGH | 7.8 | 1.0% | Apr 6, 2021 | SerenityOS fixed as of c9f25bca048443e317f1994ba9b106f2386688c3 contains a buffer overflow vulnerability in LibTextCode ... |
| CVE-2021-28075 | HIGH | 7.5 | 1.0% | Apr 6, 2021 | iKuaiOS 3.4.8 Build 202012291059 has an arbitrary file download vulnerability, which can be exploited by attackers to ob... |
| CVE-2021-27698 | CRITICAL | 9.8 | 1.2% | Apr 6, 2021 | RIOT-OS 2021.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c throug... |
| CVE-2021-27697 | CRITICAL | 9.8 | 1.3% | Apr 6, 2021 | RIOT-OS 2021.01 contains a buffer overflow vulnerability in sys/net/gnrc/routing/rpl/gnrc_rpl_validation.c through the g... |
| CVE-2021-27357 | CRITICAL | 9.8 | 1.2% | Apr 6, 2021 | RIOT-OS 2020.01 contains a buffer overflow vulnerability in /sys/net/gnrc/routing/rpl/gnrc_rpl_control_messages.c. |
| CVE-2021-27343 | HIGH | 7.5 | 1.7% | Apr 6, 2021 | SerenityOS Unspecified is affected by: Buffer Overflow. The impact is: obtain sensitive information (context-dependent).... |
| CVE-2021-28173 | CRITICAL | 9.8 | 1.6% | Apr 6, 2021 | The file upload function of Vangene deltaFlow E-platform does not perform access controlled properly. Remote attackers c... |
| CVE-2021-28172 | HIGH | 7.5 | 1.8% | Apr 6, 2021 | There is a Path Traversal vulnerability in the file download function of Vangene deltaFlow E-platform. Remote attackers ... |
| CVE-2021-28171 | CRITICAL | 9.8 | 1.2% | Apr 6, 2021 | The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain privileged permissions... |
| CVE-2021-30164 | CRITICAL | 9.8 | 1.3% | Apr 6, 2021 | Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by lev... |
| CVE-2021-30163 | HIGH | 7.5 | 1.2% | Apr 6, 2021 | Redmine before 4.0.8 and 4.1.x before 4.1.2 allows attackers to discover the names of private projects if issue-journal ... |
| CVE-2021-30162 | HIGH | 7.1 | 0.1% | Apr 6, 2021 | An issue was discovered on LG mobile devices with Android OS 4.4 through 11 software. Attackers can leverage ISMS servic... |
| CVE-2021-30161 | MEDIUM | 5.5 | 0.1% | Apr 6, 2021 | An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection... |
| CVE-2021-30158 | MEDIUM | 5.3 | 1.7% | Apr 6, 2021 | An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now