2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27940 | MEDIUM | 6.1 | 1.2% | Mar 3, 2021 | resources/public/js/orchestrator.js in openark orchestrator before 3.2.4 allows XSS via the orchestrator-msg parameter. |
| CVE-2021-27935 | HIGH | 7.5 | 4.1% | Mar 3, 2021 | An issue was discovered in AdGuard before 0.105.2. An attacker able to get the user's cookie is able to bruteforce their... |
| CVE-2021-27931 | CRITICAL | 9.1 | 18.6% | Mar 3, 2021 | LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControl... |
| CVE-2021-21314 | MEDIUM | 4.8 | 0.6% | Mar 3, 2021 | GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana... |
| CVE-2021-21313 | MEDIUM | 6.1 | 0.9% | Mar 3, 2021 | GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana... |
| CVE-2021-21312 | MEDIUM | 4.8 | 0.6% | Mar 3, 2021 | GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana... |
| CVE-2021-27839 | MEDIUM | 4.4 | 0.7% | Mar 3, 2021 | A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform ... |
| CVE-2021-22884 | HIGH | 7.5 | 32.4% | Mar 3, 2021 | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “... |
| CVE-2021-22883 | HIGH | 7.5 | 77.4% | Mar 3, 2021 | Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connecti... |
| CVE-2021-22878 | MEDIUM | 4.8 | 1.1% | Mar 3, 2021 | Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `O... |
| CVE-2021-22877 | MEDIUM | 6.5 | 1.7% | Mar 3, 2021 | A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users exter... |
| CVE-2021-22681 | CRITICAL | 9.8 | 25.5% | Mar 3, 2021 | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key ... |
| CVE-2021-22188 | MEDIUM | 5.3 | 1.3% | Mar 3, 2021 | An issue has been discovered in GitLab affecting all versions starting with 13.0. Confidential issue titles in Gitlab we... |
| CVE-2021-22182 | MEDIUM | 5.4 | 1.0% | Mar 3, 2021 | An issue has been discovered in GitLab affecting all versions starting with 13.7. GitLab was vulnerable to a stored XSS ... |
| CVE-2021-21978 | CRITICAL | 9.8 | 98.9% | Mar 3, 2021 | VMware View Planner 4.x prior to 4.6 Security Patch 1 contains a remote code execution vulnerability. Improper input val... |
| CVE-2021-27927 | HIGH | 8.8 | 1.5% | Mar 3, 2021 | In Zabbix from 4.0.x before 4.0.28rc1, 5.0.0alpha1 before 5.0.10rc1, 5.2.x before 5.2.6rc1, and 5.4.0alpha1 before 5.4.0... |
| CVE-2021-22683 | HIGH | 7.8 | 1.0% | Mar 3, 2021 | Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowi... |
| CVE-2021-22670 | HIGH | 7.8 | 1.0% | Mar 3, 2021 | An uninitialized pointer may be exploited in Fatek FvDesigner Version 1.5.76 and prior while the application is processi... |
| CVE-2021-22666 | HIGH | 7.8 | 1.1% | Mar 3, 2021 | Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a stack-based buffer overflow while project files are being p... |
| CVE-2021-22662 | HIGH | 7.8 | 1.1% | Mar 3, 2021 | A use after free issue has been identified in Fatek FvDesigner Version 1.5.76 and prior in the way the application proce... |
| CVE-2021-22638 | HIGH | 7.8 | 1.0% | Mar 3, 2021 | Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds read while processing project files, allowin... |
| CVE-2021-21979 | HIGH | 7.3 | 0.6% | Mar 3, 2021 | In Bitnami Containers, all Laravel container versions prior to: 6.20.0-debian-10-r107 for Laravel 6, 7.30.1-debian-10-r1... |
| CVE-2021-20442 | HIGH | 7.5 | 1.0% | Mar 3, 2021 | IBM Security Verify Bridge contains hard-coded credentials, such as a password or cryptographic key, which it uses for i... |
| CVE-2021-20441 | MEDIUM | 5.9 | 0.7% | Mar 3, 2021 | IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt hi... |
| CVE-2021-20233 | HIGH | 8.2 | 0.6% | Mar 3, 2021 | A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calc... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now