2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-27352MEDIUM5.4An open redirect vulnerability in Ilch CMS version 2.1.42 allows attackers to redirect users to an attacker's site after...
CVE-2021-21727HIGH7.5A ZTE product has a DoS vulnerability. A remote attacker can amplify traffic by sending carefully constructed IPv6 packe...
CVE-2021-23358HIGH7.2The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code ...
CVE-2021-28937HIGH7.5The /password.html page of the Web management interface of the Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) conta...
CVE-2021-28936HIGH7.5The Acexy Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) Web management administrator password can be changed by sending ...
CVE-2021-29274MEDIUM6.1Redmine 4.1.x before 4.1.2 allows XSS because an issue's subject is mishandled in the auto complete tip.
CVE-2021-29272MEDIUM6.1bluemonday before 1.0.5 allows XSS because certain Go lowercasing converts an uppercase Cyrillic character, defeating a ...
CVE-2021-29271MEDIUM6.1remark42 before 1.6.1 allows XSS, as demonstrated by "Locator: Locator{URL:" followed by an XSS payload. This is related...
CVE-2021-29249HIGH7.5BTCPay Server before 1.0.6.0, when the payment button is used, has a privacy vulnerability.
CVE-2021-29266HIGH7.8An issue was discovered in the Linux kernel before 5.11.9. drivers/vhost/vdpa.c has a use-after-free because v->config_c...
CVE-2021-29265MEDIUM4.7An issue was discovered in the Linux kernel before 5.11.7. usbip_sockfd_store in drivers/usb/usbip/stub_dev.c allows att...
CVE-2021-29264MEDIUM5.5An issue was discovered in the Linux kernel through 5.11.10. drivers/net/ethernet/freescale/gianfar.c in the Freescale G...
CVE-2021-21396MEDIUM6.5wire-server is an open-source back end for Wire, a secure collaboration platform. In wire-server from version 2021-02-16...
CVE-2021-21374HIGH8.1Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, ...
CVE-2021-21373MEDIUM5.9Nimble is a package manager for the Nim programming language. In Nim release versions before versions 1.2.10 and 1.4.4, ...
CVE-2021-21372HIGH8.8Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, N...
CVE-2021-20206HIGH7.2An improper limitation of path name flaw was found in containernetworking/cni in versions before 0.8.1. When specifying ...
CVE-2021-21411MEDIUM5.5OAuth2-Proxy is an open source reverse proxy that provides authentication with Google, Github or other providers. The `-...
CVE-2021-21389HIGH8.8BuddyPress is an open source WordPress plugin to build a community site. In releases of BuddyPress from 5.0.0 before 7.2...
CVE-2021-22194MEDIUM4.4In all versions of GitLab, marshalled session keys were being stored in Redis.
CVE-2021-22184MEDIUM5.5An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to se...
CVE-2021-22180MEDIUM4.3An issue has been discovered in GitLab affecting all versions starting from 13.4. Improper access control allows unautho...
CVE-2021-22172MEDIUM4.3Improper authorization in GitLab 12.8+ allows a guest user in a private project to view tag data that should be inaccess...
CVE-2021-21333MEDIUM6.1Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-21332HIGH8.2Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now