2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20218 | HIGH | 7.4 | 1.3% | Mar 16, 2021 | A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container... |
| CVE-2021-3127 | HIGH | 7.5 | 1.5% | Mar 16, 2021 | NATS Server 2.x before 2.2.0 and JWT library before 2.0.1 have Incorrect Access Control because Import Token bindings ar... |
| CVE-2021-28381 | CRITICAL | 9.8 | 1.0% | Mar 16, 2021 | The vhs (aka VHS: Fluid ViewHelpers) extension before 5.1.1 for TYPO3 allows SQL injection via isLanguageViewHelper. |
| CVE-2021-28380 | MEDIUM | 5.4 | 0.5% | Mar 16, 2021 | The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows... |
| CVE-2021-28295 | HIGH | 7.5 | 15.9% | Mar 16, 2021 | Online Ordering System 1.0 is vulnerable to unauthenticated SQL injection through /onlineordering/GPST/admin/design.php,... |
| CVE-2021-28294 | CRITICAL | 9.8 | 3.7% | Mar 16, 2021 | Online Ordering System 1.0 is vulnerable to arbitrary file upload through /onlineordering/GPST/store/initiateorder.php, ... |
| CVE-2021-27938 | MEDIUM | 6.1 | 0.8% | Mar 16, 2021 | A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs modu... |
| CVE-2021-25916 | CRITICAL | 9.8 | 3.5% | Mar 16, 2021 | Prototype pollution vulnerability in 'patchmerge' versions 1.0.0 through 1.0.1 allows an attacker to cause a denial of s... |
| CVE-2021-22887 | LOW | 2.3 | 0.2% | Mar 16, 2021 | A vulnerability in the BIOS of Pulse Secure (PSA-Series Hardware) models PSA5000 and PSA7000 could allow an attacker to ... |
| CVE-2021-28543 | HIGH | 7.5 | 1.5% | Mar 16, 2021 | Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some conf... |
| CVE-2021-21193 | HIGH | 8.8 | 9.9% | Mar 16, 2021 | Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap cor... |
| CVE-2021-21192 | HIGH | 8.8 | 1.5% | Mar 16, 2021 | Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially explo... |
| CVE-2021-21191 | HIGH | 8.8 | 1.4% | Mar 16, 2021 | Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-27230 | HIGH | 8.8 | 2.8% | Mar 15, 2021 | ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leve... |
| CVE-2021-3418 | MEDIUM | 6.4 | 0.5% | Mar 15, 2021 | If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel withou... |
| CVE-2021-26987 | CRITICAL | 9.8 | 2.4% | Mar 15, 2021 | Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are s... |
| CVE-2021-24029 | HIGH | 7.5 | 1.2% | Mar 15, 2021 | A packet of death scenario is possible in mvfst via a specially crafted message during a QUIC session, which causes a cr... |
| CVE-2021-20283 | MEDIUM | 4.3 | 1.1% | Mar 15, 2021 | The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had per... |
| CVE-2021-20282 | MEDIUM | 5.3 | 1.3% | Mar 15, 2021 | When creating a user account, it was possible to verify the account without having access to the verification email link... |
| CVE-2021-20281 | MEDIUM | 5.3 | 1.3% | Mar 15, 2021 | It was possible for some users without permission to view other users' full names to do so via the online users block in... |
| CVE-2021-20280 | MEDIUM | 5.4 | 1.3% | Mar 15, 2021 | Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3... |
| CVE-2021-20279 | MEDIUM | 5.4 | 1.0% | Mar 15, 2021 | The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.... |
| CVE-2021-3150 | MEDIUM | 6.1 | 0.6% | Mar 15, 2021 | A cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an ... |
| CVE-2021-23879 | MEDIUM | 6.7 | 0.3% | Mar 15, 2021 | Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrat... |
| CVE-2021-28363 | MEDIUM | 6.5 | 2.1% | Mar 15, 2021 | The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HT... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now