2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26688 | CRITICAL | 9.8 | 0.4% | Feb 4, 2021 | An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security pr... |
| CVE-2021-26687 | CRITICAL | 9.8 | 0.5% | Feb 4, 2021 | An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, ... |
| CVE-2021-20016 | CRITICAL | 9.8 | 37.0% | Feb 4, 2021 | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform... |
| CVE-2021-3401 | CRITICAL | 9.8 | 10.5% | Feb 4, 2021 | Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely pass... |
| CVE-2021-26024 | MEDIUM | 5.3 | 19.0% | Feb 3, 2021 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possib... |
| CVE-2021-26023 | MEDIUM | 6.1 | 25.2% | Feb 3, 2021 | The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS. |
| CVE-2021-23331 | LOW | 3.3 | 0.3% | Feb 3, 2021 | This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary fil... |
| CVE-2021-25276 | HIGH | 7.1 | 0.5% | Feb 3, 2021 | In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' pas... |
| CVE-2021-25275 | HIGH | 7.8 | 0.6% | Feb 3, 2021 | SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backen... |
| CVE-2021-25274 | CRITICAL | 9.8 | 36.4% | Feb 3, 2021 | The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set p... |
| CVE-2021-25778 | MEDIUM | 5.3 | 0.8% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly. |
| CVE-2021-25777 | MEDIUM | 5.3 | 0.7% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly. |
| CVE-2021-25776 | HIGH | 7.5 | 1.1% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters. |
| CVE-2021-25775 | LOW | 3.8 | 0.6% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. |
| CVE-2021-25774 | MEDIUM | 4.3 | 0.7% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user. |
| CVE-2021-25773 | MEDIUM | 6.1 | 0.6% | Feb 3, 2021 | JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages. |
| CVE-2021-25772 | MEDIUM | 5.3 | 1.0% | Feb 3, 2021 | In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration. |
| CVE-2021-25771 | MEDIUM | 4.3 | 1.5% | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed. |
| CVE-2021-25770 | CRITICAL | 9.8 | 3.5% | Feb 3, 2021 | In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code e... |
| CVE-2021-25769 | HIGH | 7.5 | 1.8% | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments. |
| CVE-2021-25768 | MEDIUM | 5.3 | 1.2% | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly. |
| CVE-2021-25767 | MEDIUM | 5.3 | 2.6% | Feb 3, 2021 | In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution. |
| CVE-2021-25766 | MEDIUM | 5.3 | 1.4% | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made. |
| CVE-2021-25765 | HIGH | 8.8 | 0.7% | Feb 3, 2021 | In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible. |
| CVE-2021-25763 | MEDIUM | 5.3 | 0.5% | Feb 3, 2021 | In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now