2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-28006 | MEDIUM | 6.1 | 0.9% | Mar 9, 2021 | Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter. |
| CVE-2021-20276 | HIGH | 7.5 | 2.0% | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may le... |
| CVE-2021-20275 | HIGH | 7.5 | 2.0% | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to... |
| CVE-2021-20274 | HIGH | 7.5 | 1.9% | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbeh... |
| CVE-2021-20273 | HIGH | 7.5 | 2.0% | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off. |
| CVE-2021-20272 | HIGH | 7.5 | 2.1% | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to... |
| CVE-2021-24033 | MEDIUM | 5.6 | 3.3% | Mar 9, 2021 | react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a c... |
| CVE-2021-21361 | MEDIUM | 6.5 | 1.2% | Mar 9, 2021 | The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the loggi... |
| CVE-2021-21360 | MEDIUM | 5.3 | 1.5% | Mar 9, 2021 | Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem arti... |
| CVE-2021-21510 | MEDIUM | 6.1 | 1.0% | Mar 8, 2021 | Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attack... |
| CVE-2021-21506 | HIGH | 8.8 | 1.0% | Mar 8, 2021 | PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in its API handler. An un-authtenti... |
| CVE-2021-21503 | HIGH | 7.8 | 0.3% | Mar 8, 2021 | PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user co... |
| CVE-2021-22134 | MEDIUM | 4.3 | 1.1% | Mar 8, 2021 | A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Leve... |
| CVE-2021-21337 | MEDIUM | 6.1 | 8.4% | Mar 8, 2021 | Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS... |
| CVE-2021-21336 | MEDIUM | 6.5 | 1.5% | Mar 8, 2021 | Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS... |
| CVE-2021-21335 | CRITICAL | 9.8 | 1.7% | Mar 8, 2021 | In the SPNEGO HTTP Authentication Module for nginx (spnego-http-auth-nginx-module) before version 1.1.1 basic Authentica... |
| CVE-2021-21362 | MEDIUM | 6.5 | 1.3% | Mar 8, 2021 | MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage se... |
| CVE-2021-21354 | MEDIUM | 6.1 | 1.4% | Mar 8, 2021 | Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things... |
| CVE-2021-21329 | CRITICAL | 9.8 | 1.5% | Mar 8, 2021 | RATCF is an open-source framework for hosting Cyber-Security Capture the Flag events. In affected versions of RATCF user... |
| CVE-2021-21327 | HIGH | 7.5 | 2.3% | Mar 8, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2021-21326 | MEDIUM | 6.5 | 1.4% | Mar 8, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2021-21325 | MEDIUM | 4.8 | 0.6% | Mar 8, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2021-21324 | MEDIUM | 6.5 | 1.4% | Mar 8, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2021-27222 | MEDIUM | 5.4 | 0.9% | Mar 8, 2021 | In the "Time in Status" app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS. |
| CVE-2021-26788 | HIGH | 7.5 | 1.2% | Mar 8, 2021 | Oryx Embedded CycloneTCP 1.7.6 to 2.0.0, fixed in 2.0.2, is affected by incorrect input validation, which may cause a de... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now