2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-28971MEDIUM5.5In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, users...
CVE-2021-27596LOW3.3When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visua...
CVE-2021-27595LOW3.3When a user opens manipulated Portable Document Format (.PDF) files received from untrusted sources in SAP 3D Visual Ent...
CVE-2021-27594LOW3.3When a user opens manipulated Windows Bitmap (.BMP) files received from untrusted sources in SAP 3D Visual Enterprise Vi...
CVE-2021-27593LOW3.3When a user opens manipulated Graphics Interchange Format (.GIF) files received from untrusted sources in SAP 3D Visual ...
CVE-2021-28968MEDIUM5.4An issue was discovered in PunBB before 1.4.6. An XSS vulnerability in the [email] BBcode tag allows (with authenticatio...
CVE-2021-28148HIGH7.5One of the usage insights HTTP API endpoints in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before...
CVE-2021-28147MEDIUM6.5The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrec...
CVE-2021-27308MEDIUM4.8A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to in...
CVE-2021-28146MEDIUM6.5The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instan...
CVE-2021-27962HIGH7.1Grafana Enterprise 7.2.x and 7.3.x before 7.3.10 and 7.4.x before 7.4.5 allows a dashboard editor to bypass a permission...
CVE-2021-26295CRITICAL9.8Apache OFBiz has unsafe deserialization prior to 17.12.06. An unauthenticated attacker can use this vulnerability to suc...
CVE-2021-28964MEDIUM4.7A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attack...
CVE-2021-21438MEDIUM4.3Agents are able to see linked FAQ articles without permissions (defined in FAQ Category). This issue affects: FAQ versio...
CVE-2021-21437MEDIUM4.3Agents are able to see linked Config Items without permissions, which are defined in General Catalog. This issue affects...
CVE-2021-28963MEDIUM5.3Shibboleth Service Provider before 3.2.1 allows content injection because template generation uses attacker-controlled p...
CVE-2021-28956HIGH8.8The unofficial vscode-sass-lint (aka Sass Lint) extension through 1.0.7 for Visual Studio Code allows attackers to execu...
CVE-2021-28955CRITICAL9.8git-bug before 0.7.2 has an Uncontrolled Search Path Element. It will execute git.bat from the current directory in cert...
CVE-2021-26070HIGH7.2Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protectio...
CVE-2021-26069MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary ...
CVE-2021-23360HIGH8.8This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an atta...
CVE-2021-28961HIGH8.8applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenti...
CVE-2021-28957MEDIUM6.1An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_o...
CVE-2021-28954HIGH7.8In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository.
CVE-2021-28953HIGH7.8The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary b...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now