2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21622 | MEDIUM | 5.4 | 9.4% | Feb 24, 2021 | Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulti... |
| CVE-2021-21621 | MEDIUM | 5.3 | 1.2% | Feb 24, 2021 | Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (bas... |
| CVE-2021-21620 | MEDIUM | 4.3 | 1.6% | Feb 24, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change ... |
| CVE-2021-21619 | MEDIUM | 5.4 | 9.4% | Feb 24, 2021 | Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scriptin... |
| CVE-2021-21618 | MEDIUM | 5.4 | 82.2% | Feb 24, 2021 | Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, ... |
| CVE-2021-21617 | HIGH | 8.8 | 0.9% | Feb 24, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Configuration Slicing Plugin 1.51 and earlier allows attack... |
| CVE-2021-21616 | MEDIUM | 4.6 | 78.8% | Feb 24, 2021 | Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-... |
| CVE-2021-3355 | MEDIUM | 5.4 | 7.3% | Feb 24, 2021 | A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Tit... |
| CVE-2021-27645 | LOW | 2.5 | 0.4% | Feb 24, 2021 | The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a requ... |
| CVE-2021-20662 | HIGH | 7.5 | 2.1% | Feb 24, 2021 | Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to al... |
| CVE-2021-20661 | HIGH | 8.1 | 2.4% | Feb 24, 2021 | Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to d... |
| CVE-2021-20660 | MEDIUM | 6.1 | 46.9% | Feb 24, 2021 | Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an ar... |
| CVE-2021-20659 | HIGH | 8.8 | 2.1% | Feb 24, 2021 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecifi... |
| CVE-2021-20658 | CRITICAL | 9.8 | 3.7% | Feb 24, 2021 | SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server ... |
| CVE-2021-20657 | MEDIUM | 5.4 | 2.7% | Feb 24, 2021 | Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacke... |
| CVE-2021-20656 | MEDIUM | 4.3 | 1.1% | Feb 24, 2021 | Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authentic... |
| CVE-2021-3410 | HIGH | 7.8 | 0.6% | Feb 23, 2021 | A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may l... |
| CVE-2021-3407 | MEDIUM | 5.5 | 50.5% | Feb 23, 2021 | A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other pot... |
| CVE-2021-21323 | MEDIUM | 5.3 | 1.9% | Feb 23, 2021 | Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME ... |
| CVE-2021-20256 | MEDIUM | 5.3 | 0.3% | Feb 23, 2021 | A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local ... |
| CVE-2021-20252 | MEDIUM | 6.5 | 1.0% | Feb 23, 2021 | A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on... |
| CVE-2021-20194 | HIGH | 7.8 | 0.4% | Feb 23, 2021 | There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_... |
| CVE-2021-20182 | HIGH | 8.8 | 1.1% | Feb 23, 2021 | A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges us... |
| CVE-2021-3405 | MEDIUM | 6.5 | 1.7% | Feb 23, 2021 | A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and E... |
| CVE-2021-26927 | MEDIUM | 5.5 | 1.1% | Feb 23, 2021 | A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program cras... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now