2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-25924HIGH8.8In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/...
CVE-2021-22890LOW3.7curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due ...
CVE-2021-22876MEDIUM5.3curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Acto...
CVE-2021-22195HIGH7.8Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system
CVE-2021-20291MEDIUM6.5A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image ...
CVE-2021-28165HIGH7.5In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon re...
CVE-2021-28164MEDIUM5.3In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai...
CVE-2021-28163LOW2.7In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps director...
CVE-2021-22177MEDIUM4.3Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike ...
CVE-2021-3393MEDIUM4.3An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UP...
CVE-2021-28546MEDIUM6.5Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e...
CVE-2021-28545HIGH8.1Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e...
CVE-2021-20296MEDIUM5.3A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is process...
CVE-2021-20235HIGH8.1There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator...
CVE-2021-20234MEDIUM6.5An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/p...
CVE-2021-28918CRITICAL9.1Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attacke...
CVE-2021-29083HIGH7.2Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Man...
CVE-2021-29942HIGH7.3An issue was discovered in the reorder crate through 2021-02-24 for Rust. swap_index can return uninitialized values if ...
CVE-2021-29941HIGH7.3An issue was discovered in the reorder crate through 2021-02-24 for Rust. swap_index has an out-of-bounds write if an it...
CVE-2021-29940CRITICAL9.8An issue was discovered in the through crate through 2021-02-18 for Rust. There is a double free (in through and through...
CVE-2021-29939HIGH7.3An issue was discovered in the stackvector crate through 2021-02-19 for Rust. There is an out-of-bounds write in StackVe...
CVE-2021-29938HIGH7.5An issue was discovered in the slice-deque crate through 2021-02-19 for Rust. A double drop can occur in SliceDeque::dra...
CVE-2021-29937CRITICAL9.8An issue was discovered in the telemetry crate through 2021-02-17 for Rust. There is a drop of uninitialized memory if a...
CVE-2021-29936CRITICAL9.8An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via t...
CVE-2021-29935HIGH7.3An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-pr...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now