2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28971 | MEDIUM | 5.5 | 0.4% | Mar 22, 2021 | In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, users... |
| CVE-2021-27596 | LOW | 3.3 | 0.7% | Mar 22, 2021 | When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visua... |
| CVE-2021-27595 | LOW | 3.3 | 1.4% | Mar 22, 2021 | When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Ent... |
| CVE-2021-27594 | LOW | 3.3 | 0.6% | Mar 22, 2021 | When a user opens manipulated Windows Bitmap (.BMP) files received from untrusted sources in SAP 3D Visual Enterprise Vi... |
| CVE-2021-27593 | LOW | 3.3 | 0.6% | Mar 22, 2021 | When a user opens manipulated Graphics Interchange Format (.GIF) files received from untrusted sources in SAP 3D Visual ... |
| CVE-2021-28968 | MEDIUM | 5.4 | 0.5% | Mar 22, 2021 | An issue was discovered in PunBB before 1.4.6. An XSS vulnerability in the [email] BBcode tag allows (with authenticatio... |
| CVE-2021-28148 | HIGH | 7.5 | 3.5% | Mar 22, 2021 | One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before... |
| CVE-2021-28147 | MEDIUM | 6.5 | 1.6% | Mar 22, 2021 | The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrec... |
| CVE-2021-27308 | MEDIUM | 4.8 | 2.2% | Mar 22, 2021 | A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to in... |
| CVE-2021-28146 | MEDIUM | 6.5 | 1.4% | Mar 22, 2021 | The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instan... |
| CVE-2021-27962 | HIGH | 7.1 | 2.1% | Mar 22, 2021 | Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission... |
| CVE-2021-26295 | CRITICAL | 9.8 | 98.0% | Mar 22, 2021 | Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to suc... |
| CVE-2021-28964 | MEDIUM | 4.7 | 0.3% | Mar 22, 2021 | A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attack... |
| CVE-2021-21438 | MEDIUM | 4.3 | 0.6% | Mar 22, 2021 | Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ versio... |
| CVE-2021-21437 | MEDIUM | 4.3 | 0.7% | Mar 22, 2021 | Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects... |
| CVE-2021-28963 | MEDIUM | 5.3 | 1.3% | Mar 22, 2021 | Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled p... |
| CVE-2021-28956 | HIGH | 8.8 | 1.5% | Mar 22, 2021 | The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execu... |
| CVE-2021-28955 | CRITICAL | 9.8 | 1.5% | Mar 22, 2021 | git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in cert... |
| CVE-2021-26070 | HIGH | 7.2 | 2.0% | Mar 22, 2021 | Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protectio... |
| CVE-2021-26069 | MEDIUM | 5.3 | 2.5% | Mar 22, 2021 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary ... |
| CVE-2021-23360 | HIGH | 8.8 | 2.3% | Mar 21, 2021 | This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an atta... |
| CVE-2021-28961 | HIGH | 8.8 | 1.5% | Mar 21, 2021 | applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenti... |
| CVE-2021-28957 | MEDIUM | 6.1 | 4.0% | Mar 21, 2021 | An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_o... |
| CVE-2021-28954 | HIGH | 7.8 | 1.0% | Mar 21, 2021 | In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository. |
| CVE-2021-28953 | HIGH | 7.8 | 1.0% | Mar 21, 2021 | The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary b... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now