2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21305 | HIGH | 8.8 | 12.7% | Feb 8, 2021 | CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. I... |
| CVE-2021-21290 | MEDIUM | 5.5 | 1.8% | Feb 8, 2021 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h... |
| CVE-2021-21288 | MEDIUM | 4.3 | 1.2% | Feb 8, 2021 | CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. I... |
| CVE-2021-21240 | HIGH | 7.5 | 3.9% | Feb 8, 2021 | httplib2 is a comprehensive HTTP client library for Python. In httplib2 before version 0.19.0, a malicious server which ... |
| CVE-2021-26572 | HIGH | 7.8 | 0.3% | Feb 8, 2021 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ... |
| CVE-2021-26571 | HIGH | 7.8 | 0.3% | Feb 8, 2021 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ... |
| CVE-2021-26570 | HIGH | 7.8 | 0.5% | Feb 8, 2021 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ... |
| CVE-2021-25171 | HIGH | 7.8 | 0.3% | Feb 8, 2021 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ... |
| CVE-2021-25170 | HIGH | 7.8 | 0.3% | Feb 8, 2021 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ... |
| CVE-2021-25169 | HIGH | 7.8 | 0.3% | Feb 8, 2021 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ... |
| CVE-2021-25168 | HIGH | 7.8 | 0.3% | Feb 8, 2021 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ... |
| CVE-2021-25837 | HIGH | 7.5 | 1.5% | Feb 8, 2021 | Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. Due to the inconsiste... |
| CVE-2021-25836 | HIGH | 7.5 | 1.3% | Feb 8, 2021 | Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a... |
| CVE-2021-25835 | HIGH | 7.5 | 1.3% | Feb 8, 2021 | Cosmos Network Ethermint <= v0.4.0 is affected by a cross-chain transaction replay vulnerability in the EVM module. Sinc... |
| CVE-2021-25834 | HIGH | 7.5 | 1.1% | Feb 8, 2021 | Cosmos Network Ethermint <= v0.4.0 is affected by a transaction replay vulnerability in the EVM module. If the victim se... |
| CVE-2021-25142 | HIGH | 7.8 | 0.3% | Feb 8, 2021 | The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer ... |
| CVE-2021-21304 | CRITICAL | 9.8 | 1.9% | Feb 8, 2021 | Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.... |
| CVE-2021-26541 | CRITICAL | 9.8 | 5.4% | Feb 8, 2021 | The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability. |
| CVE-2021-26540 | MEDIUM | 5.3 | 1.8% | Feb 8, 2021 | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHos... |
| CVE-2021-26539 | MEDIUM | 5.3 | 2.0% | Feb 8, 2021 | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which co... |
| CVE-2021-22122 | MEDIUM | 6.1 | 10.5% | Feb 8, 2021 | An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version... |
| CVE-2021-3293 | MEDIUM | 5.3 | 17.4% | Feb 8, 2021 | emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webr... |
| CVE-2021-26826 | HIGH | 7.8 | 1.5% | Feb 8, 2021 | A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA ima... |
| CVE-2021-26825 | HIGH | 7.8 | 1.5% | Feb 8, 2021 | An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA ima... |
| CVE-2021-20359 | MEDIUM | 6.5 | 1.3% | Feb 8, 2021 | IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentiall... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now