2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27352 | MEDIUM | 5.4 | 0.8% | Mar 29, 2021 | An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after... |
| CVE-2021-21727 | HIGH | 7.5 | 1.4% | Mar 29, 2021 | A ZTE product has a DoS vulnerability. A remote attacker can amplify traffic by sending carefully constructed IPv6 packe... |
| CVE-2021-23358 | HIGH | 7.2 | 4.1% | Mar 29, 2021 | The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code ... |
| CVE-2021-28937 | HIGH | 7.5 | 5.3% | Mar 29, 2021 | The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) conta... |
| CVE-2021-28936 | HIGH | 7.5 | 2.6% | Mar 29, 2021 | The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending ... |
| CVE-2021-29274 | MEDIUM | 6.1 | 0.8% | Mar 29, 2021 | Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip. |
| CVE-2021-29272 | MEDIUM | 6.1 | 0.9% | Mar 27, 2021 | bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a ... |
| CVE-2021-29271 | MEDIUM | 6.1 | 0.8% | Mar 27, 2021 | remark42 before 1.6.1 allows XSS, as demonstrated by "Locator: Locator{URL:" followed by an XSS payload. This is related... |
| CVE-2021-29249 | HIGH | 7.5 | 1.2% | Mar 26, 2021 | BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability. |
| CVE-2021-29266 | HIGH | 7.8 | 0.3% | Mar 26, 2021 | An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_c... |
| CVE-2021-29265 | MEDIUM | 4.7 | 0.3% | Mar 26, 2021 | An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows att... |
| CVE-2021-29264 | MEDIUM | 5.5 | 0.3% | Mar 26, 2021 | An issue was discovered in the Linux kernel through 5.11.10. drivers/net/ethernet/freescale/gianfar.c in the Freescale G... |
| CVE-2021-21396 | MEDIUM | 6.5 | 1.1% | Mar 26, 2021 | wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16... |
| CVE-2021-21374 | HIGH | 8.1 | 1.0% | Mar 26, 2021 | Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, ... |
| CVE-2021-21373 | MEDIUM | 5.9 | 1.2% | Mar 26, 2021 | Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, ... |
| CVE-2021-21372 | HIGH | 8.8 | 3.6% | Mar 26, 2021 | Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, N... |
| CVE-2021-20206 | HIGH | 7.2 | 1.5% | Mar 26, 2021 | An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying ... |
| CVE-2021-21411 | MEDIUM | 5.5 | 1.0% | Mar 26, 2021 | OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `-... |
| CVE-2021-21389 | HIGH | 8.8 | 13.9% | Mar 26, 2021 | BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2... |
| CVE-2021-22194 | MEDIUM | 4.4 | 0.2% | Mar 26, 2021 | In all versions of GitLab, marshalled session keys were being stored in Redis. |
| CVE-2021-22184 | MEDIUM | 5.5 | 0.3% | Mar 26, 2021 | An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to se... |
| CVE-2021-22180 | MEDIUM | 4.3 | 0.9% | Mar 26, 2021 | An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unautho... |
| CVE-2021-22172 | MEDIUM | 4.3 | 1.0% | Mar 26, 2021 | Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccess... |
| CVE-2021-21333 | MEDIUM | 6.1 | 1.4% | Mar 26, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
| CVE-2021-21332 | HIGH | 8.2 | 1.2% | Mar 26, 2021 | Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now