2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-25762 | MEDIUM | 5.3 | 0.8% | Feb 3, 2021 | In JetBrains Ktor before 1.4.3, HTTP Request Smuggling was possible. |
| CVE-2021-25761 | MEDIUM | 5.3 | 0.5% | Feb 3, 2021 | In JetBrains Ktor before 1.5.0, a birthday attack on SessionStorage key was possible. |
| CVE-2021-25760 | MEDIUM | 5.3 | 0.9% | Feb 3, 2021 | In JetBrains Hub before 2020.1.12669, information disclosure via the public API was possible. |
| CVE-2021-25759 | MEDIUM | 6.5 | 0.7% | Feb 3, 2021 | In JetBrains Hub before 2020.1.12629, an authenticated user can delete 2FA settings of any other user. |
| CVE-2021-25758 | HIGH | 7.8 | 1.0% | Feb 3, 2021 | In JetBrains IntelliJ IDEA before 2020.3, potentially insecure deserialization of the workspace model could lead to loca... |
| CVE-2021-25757 | MEDIUM | 6.1 | 0.6% | Feb 3, 2021 | In JetBrains Hub before 2020.1.12629, an open redirect was possible. |
| CVE-2021-25756 | MEDIUM | 5.3 | 1.3% | Feb 3, 2021 | In JetBrains IntelliJ IDEA before 2020.2, HTTP links were used for several remote repositories instead of HTTPS. |
| CVE-2021-25755 | LOW | 2.5 | 0.4% | Feb 3, 2021 | In JetBrains Code With Me before 2020.3, an attacker on the local network, knowing a session ID, could get access to the... |
| CVE-2021-0365 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In display driver, there is a possible memory corruption due to a use after free. This could lead to local escalation of... |
| CVE-2021-0364 | MEDIUM | 6.7 | 0.3% | Feb 3, 2021 | In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escala... |
| CVE-2021-0363 | MEDIUM | 6.7 | 0.3% | Feb 3, 2021 | In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalatio... |
| CVE-2021-0362 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In aee, there is a possible memory corruption due to a stack buffer overflow. This could lead to local escalation of pri... |
| CVE-2021-0361 | MEDIUM | 6.7 | 0.1% | Feb 3, 2021 | In kisd, there is a possible out of bounds read due to improper input validation. This could lead to local escalation of... |
| CVE-2021-0360 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In netdiag, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalatio... |
| CVE-2021-0359 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2021-0358 | MEDIUM | 6.7 | 0.3% | Feb 3, 2021 | In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation ... |
| CVE-2021-0357 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In netdiag, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o... |
| CVE-2021-0356 | MEDIUM | 6.7 | 0.3% | Feb 3, 2021 | In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation ... |
| CVE-2021-0355 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In kisd, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of priv... |
| CVE-2021-0354 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In ged, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi... |
| CVE-2021-0353 | MEDIUM | 6.7 | 0.2% | Feb 3, 2021 | In kisd, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of pri... |
| CVE-2021-0352 | MEDIUM | 4.4 | 0.1% | Feb 3, 2021 | In RT regmap driver, there is a possible memory corruption due to type confusion. This could lead to local denial of ser... |
| CVE-2021-21043 | MEDIUM | 6.1 | 3.3% | Feb 2, 2021 | ACS Commons version 4.9.2 (and earlier) suffers from a Reflected Cross-site Scripting (XSS) vulnerability in version-com... |
| CVE-2021-21294 | HIGH | 7.5 | 2.1% | Feb 2, 2021 | Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Http4s before versions 0.21.17, ... |
| CVE-2021-21293 | HIGH | 7.5 | 2.1% | Feb 2, 2021 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. All servers running blaze-core... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now