2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-26688CRITICAL9.8An issue was discovered on LG Wing mobile devices with Android OS 10 software. The biometric sensor has weak security pr...
CVE-2021-26687CRITICAL9.8An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10 software. In preloaded applications, ...
CVE-2021-20016CRITICAL9.8A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform...
CVE-2021-3401CRITICAL9.8Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely pass...
CVE-2021-26024MEDIUM5.3The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possib...
CVE-2021-26023MEDIUM6.1The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to XSS.
CVE-2021-23331LOW3.3This affects all versions of package com.squareup:connect. The method prepareDownloadFilecreates creates a temporary fil...
CVE-2021-25276HIGH7.1In SolarWinds Serv-U before 15.2.2 Hotfix 1, there is a directory containing user profile files (that include users' pas...
CVE-2021-25275HIGH7.8SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backen...
CVE-2021-25274CRITICAL9.8The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set p...
CVE-2021-25778MEDIUM5.3In JetBrains TeamCity before 2020.2.1, permissions during user deletion were checked improperly.
CVE-2021-25777MEDIUM5.3In JetBrains TeamCity before 2020.2.1, permissions during token removal were checked improperly.
CVE-2021-25776HIGH7.5In JetBrains TeamCity before 2020.2, an ECR token could be exposed in a build's parameters.
CVE-2021-25775LOW3.8In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
CVE-2021-25774MEDIUM4.3In JetBrains TeamCity before 2020.2.1, a user could get access to the GitHub access token of another user.
CVE-2021-25773MEDIUM6.1JetBrains TeamCity before 2020.2 was vulnerable to reflected XSS on several pages.
CVE-2021-25772MEDIUM5.3In JetBrains TeamCity before 2020.2.2, TeamCity server DoS was possible via server integration.
CVE-2021-25771MEDIUM4.3In JetBrains YouTrack before 2020.6.1099, project information could be potentially disclosed.
CVE-2021-25770CRITICAL9.8In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code e...
CVE-2021-25769HIGH7.5In JetBrains YouTrack before 2020.4.6808, the YouTrack administrator wasn't able to access attachments.
CVE-2021-25768MEDIUM5.3In JetBrains YouTrack before 2020.4.4701, permissions for attachments actions were checked improperly.
CVE-2021-25767MEDIUM5.3In JetBrains YouTrack before 2020.6.1767, an issue's existence could be disclosed via YouTrack command execution.
CVE-2021-25766MEDIUM5.3In JetBrains YouTrack before 2020.4.4701, improper resource access checks were made.
CVE-2021-25765HIGH8.8In JetBrains YouTrack before 2020.4.4701, CSRF via attachment upload was possible.
CVE-2021-25763MEDIUM5.3In JetBrains Ktor before 1.4.2, weak cipher suites were enabled by default.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now