2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-28006MEDIUM6.1Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter.
CVE-2021-20276HIGH7.5A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may le...
CVE-2021-20275HIGH7.5A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to...
CVE-2021-20274HIGH7.5A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbeh...
CVE-2021-20273HIGH7.5A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.
CVE-2021-20272HIGH7.5A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to...
CVE-2021-24033MEDIUM5.6react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a c...
CVE-2021-21361MEDIUM6.5The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the loggi...
CVE-2021-21360MEDIUM5.3Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem arti...
CVE-2021-21510MEDIUM6.1Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attack...
CVE-2021-21506HIGH8.8PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenti...
CVE-2021-21503HIGH7.8PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user co...
CVE-2021-22134MEDIUM4.3A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Leve...
CVE-2021-21337MEDIUM6.1Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS...
CVE-2021-21336MEDIUM6.5Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS...
CVE-2021-21335CRITICAL9.8In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentica...
CVE-2021-21362MEDIUM6.5MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage se...
CVE-2021-21354MEDIUM6.1Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things...
CVE-2021-21329CRITICAL9.8RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF user...
CVE-2021-21327HIGH7.5GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2021-21326MEDIUM6.5GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2021-21325MEDIUM4.8GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2021-21324MEDIUM6.5GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2021-27222MEDIUM5.4In the "Time in Status" app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS.
CVE-2021-26788HIGH7.5Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a de...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now