2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-20218HIGH7.4A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container...
CVE-2021-3127HIGH7.5NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings ar...
CVE-2021-28381CRITICAL9.8The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper.
CVE-2021-28380MEDIUM5.4The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows...
CVE-2021-28295HIGH7.5Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php,...
CVE-2021-28294CRITICAL9.8Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, ...
CVE-2021-27938MEDIUM6.1A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs modu...
CVE-2021-25916CRITICAL9.8Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of s...
CVE-2021-22887LOW2.3A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to ...
CVE-2021-28543HIGH7.5Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some conf...
CVE-2021-21193HIGH8.8Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap cor...
CVE-2021-21192HIGH8.8Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially explo...
CVE-2021-21191HIGH8.8Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap co...
CVE-2021-27230HIGH8.8ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leve...
CVE-2021-3418MEDIUM6.4If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel withou...
CVE-2021-26987CRITICAL9.8Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are s...
CVE-2021-24029HIGH7.5A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a cr...
CVE-2021-20283MEDIUM4.3The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had per...
CVE-2021-20282MEDIUM5.3When creating a user account, it was possible to verify the account without having access to the verification email link...
CVE-2021-20281MEDIUM5.3It was possible for some users without permission to view other users' full names to do so via the online users block in...
CVE-2021-20280MEDIUM5.4Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3...
CVE-2021-20279MEDIUM5.4The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3....
CVE-2021-3150MEDIUM6.1A cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an ...
CVE-2021-23879MEDIUM6.7Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrat...
CVE-2021-28363MEDIUM6.5The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HT...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now