2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-3395MEDIUM5.4A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary f...
CVE-2021-21292MEDIUM6.3Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path v...
CVE-2021-25912CRITICAL9.8Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service ...
CVE-2021-23271HIGH8The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows...
CVE-2021-21291MEDIUM6.1OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google...
CVE-2021-21289HIGH8.3Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and ...
CVE-2021-20199MEDIUM5.9Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote ho...
CVE-2021-21285MEDIUM6.5In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker i...
CVE-2021-21284MEDIUM6.8In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access ...
CVE-2021-25310HIGH8.8The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated a...
CVE-2021-3281MEDIUM5.3In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "...
CVE-2021-20207Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:CVE-2021-3348. Reason: This candidate is a reservation dup...
CVE-2021-3378CRITICAL9.8FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl...
CVE-2021-3340MEDIUM6.1A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote att...
CVE-2021-21287HIGH7.7MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-3...
CVE-2021-3283HIGH7.5HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other ...
CVE-2021-3282HIGH7.5HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secon...
CVE-2021-3024MEDIUM5.3HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid...
CVE-2021-21286HIGH8.8AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. In AVideo Platform b...
CVE-2021-23330CRITICAL9.8All versions of package launchpad are vulnerable to Command Injection via stop.
CVE-2021-21277HIGH8.8angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-exp...
CVE-2021-21276CRITICAL9.3Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attacker...
CVE-2021-21266MEDIUM5openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2....
CVE-2021-3350MEDIUM6.1deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter.
CVE-2021-3349LOW3.3GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted ke...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now