2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-21305HIGH8.8CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. I...
CVE-2021-21290MEDIUM5.5Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h...
CVE-2021-21288MEDIUM4.3CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. I...
CVE-2021-21240HIGH7.5httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which ...
CVE-2021-26572HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-26571HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-26570HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-25171HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-25170HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-25169HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-25168HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-25837HIGH7.5Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsiste...
CVE-2021-25836HIGH7.5Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a...
CVE-2021-25835HIGH7.5Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Sinc...
CVE-2021-25834HIGH7.5Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim se...
CVE-2021-25142HIGH7.8The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ...
CVE-2021-21304CRITICAL9.8Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7....
CVE-2021-26541CRITICAL9.8The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability.
CVE-2021-26540MEDIUM5.3Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHos...
CVE-2021-26539MEDIUM5.3Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which co...
CVE-2021-22122MEDIUM6.1An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version...
CVE-2021-3293MEDIUM5.3emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webr...
CVE-2021-26826HIGH7.8A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA ima...
CVE-2021-26825HIGH7.8An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA ima...
CVE-2021-20359MEDIUM6.5IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentiall...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now