2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25924 | HIGH | 8.8 | 0.8% | Apr 1, 2021 | In GoCD, versions 19.6.0 to 21.1.0 are vulnerable to Cross-Site Request Forgery due to missing CSRF protection at the `/... |
| CVE-2021-22890 | LOW | 3.7 | 3.1% | Apr 1, 2021 | curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due ... |
| CVE-2021-22876 | MEDIUM | 5.3 | 5.3% | Apr 1, 2021 | curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Acto... |
| CVE-2021-22195 | HIGH | 7.8 | 1.1% | Apr 1, 2021 | Client side code execution in gitlab-vscode-extension v3.15.0 and earlier allows attacker to execute code on user system |
| CVE-2021-20291 | MEDIUM | 6.5 | 1.6% | Apr 1, 2021 | A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image ... |
| CVE-2021-28165 | HIGH | 7.5 | 53.9% | Apr 1, 2021 | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon re... |
| CVE-2021-28164 | MEDIUM | 5.3 | 82.4% | Apr 1, 2021 | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai... |
| CVE-2021-28163 | LOW | 2.7 | 4.2% | Apr 1, 2021 | In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps director... |
| CVE-2021-22177 | MEDIUM | 4.3 | 1.2% | Apr 1, 2021 | Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike ... |
| CVE-2021-3393 | MEDIUM | 4.3 | 1.2% | Apr 1, 2021 | An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UP... |
| CVE-2021-28546 | MEDIUM | 6.5 | 1.4% | Apr 1, 2021 | Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e... |
| CVE-2021-28545 | HIGH | 8.1 | 2.3% | Apr 1, 2021 | Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e... |
| CVE-2021-20296 | MEDIUM | 5.3 | 1.7% | Apr 1, 2021 | A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is process... |
| CVE-2021-20235 | HIGH | 8.1 | 43.9% | Apr 1, 2021 | There's a flaw in the zeromq server in versions before 4.3.3 in src/decoder_allocators.hpp. The decoder static allocator... |
| CVE-2021-20234 | MEDIUM | 6.5 | 1.1% | Apr 1, 2021 | An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/p... |
| CVE-2021-28918 | CRITICAL | 9.1 | 16.4% | Apr 1, 2021 | Improper input validation of octal strings in netmask npm package v1.0.6 and below allows unauthenticated remote attacke... |
| CVE-2021-29083 | HIGH | 7.2 | 2.6% | Apr 1, 2021 | Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Man... |
| CVE-2021-29942 | HIGH | 7.3 | 0.9% | Apr 1, 2021 | An issue was discovered in the reorder crate through 2021-02-24 for Rust. swap_index can return uninitialized values if ... |
| CVE-2021-29941 | HIGH | 7.3 | 0.9% | Apr 1, 2021 | An issue was discovered in the reorder crate through 2021-02-24 for Rust. swap_index has an out-of-bounds write if an it... |
| CVE-2021-29940 | CRITICAL | 9.8 | 1.3% | Apr 1, 2021 | An issue was discovered in the through crate through 2021-02-18 for Rust. There is a double free (in through and through... |
| CVE-2021-29939 | HIGH | 7.3 | 1.0% | Apr 1, 2021 | An issue was discovered in the stackvector crate through 2021-02-19 for Rust. There is an out-of-bounds write in StackVe... |
| CVE-2021-29938 | HIGH | 7.5 | 1.1% | Apr 1, 2021 | An issue was discovered in the slice-deque crate through 2021-02-19 for Rust. A double drop can occur in SliceDeque::dra... |
| CVE-2021-29937 | CRITICAL | 9.8 | 1.4% | Apr 1, 2021 | An issue was discovered in the telemetry crate through 2021-02-17 for Rust. There is a drop of uninitialized memory if a... |
| CVE-2021-29936 | CRITICAL | 9.8 | 1.3% | Apr 1, 2021 | An issue was discovered in the adtensor crate through 2021-01-11 for Rust. There is a drop of uninitialized memory via t... |
| CVE-2021-29935 | HIGH | 7.3 | 1.0% | Apr 1, 2021 | An issue was discovered in the rocket crate before 0.4.7 for Rust. uri::Formatter can have a use-after-free if a user-pr... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now