2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21622MEDIUM5.4Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulti...
CVE-2021-21621MEDIUM5.3Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (bas...
CVE-2021-21620MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change ...
CVE-2021-21619MEDIUM5.4Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scriptin...
CVE-2021-21618MEDIUM5.4Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, ...
CVE-2021-21617HIGH8.8A cross-site request forgery (CSRF) vulnerability in Jenkins Configuration Slicing Plugin 1.51 and earlier allows attack...
CVE-2021-21616MEDIUM4.6Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-...
CVE-2021-3355MEDIUM5.4A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Tit...
CVE-2021-27645LOW2.5The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a requ...
CVE-2021-20662HIGH7.5Missing authentication for critical function in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to al...
CVE-2021-20661HIGH8.1Directory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to d...
CVE-2021-20660MEDIUM6.1Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an ar...
CVE-2021-20659HIGH8.8SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecifi...
CVE-2021-20658CRITICAL9.8SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server ...
CVE-2021-20657MEDIUM5.4Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacke...
CVE-2021-20656MEDIUM4.3Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authentic...
CVE-2021-3410HIGH7.8A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may l...
CVE-2021-3407MEDIUM5.5A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other pot...
CVE-2021-21323MEDIUM5.3Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME ...
CVE-2021-20256MEDIUM5.3A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local ...
CVE-2021-20252MEDIUM6.5A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on...
CVE-2021-20194HIGH7.8There is a vulnerability in the linux kernel versions higher than 5.2 (if kernel compiled with config params CONFIG_BPF_...
CVE-2021-20182HIGH8.8A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges us...
CVE-2021-3405MEDIUM6.5A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and E...
CVE-2021-26927MEDIUM5.5A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program cras...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now