2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3395 | MEDIUM | 5.4 | 0.8% | Feb 2, 2021 | A cross-site scripting (XSS) vulnerability in Pryaniki 6.44.3 allows remote authenticated users to upload an arbitrary f... |
| CVE-2021-21292 | MEDIUM | 6.3 | 0.4% | Feb 2, 2021 | Traccar is an open source GPS tracking system. In Traccar before version 4.12 there is an unquoted Windows binary path v... |
| CVE-2021-25912 | CRITICAL | 9.8 | 3.3% | Feb 2, 2021 | Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service ... |
| CVE-2021-23271 | HIGH | 8 | 0.9% | Feb 2, 2021 | The TIBCO EBX Web Server component of TIBCO Software Inc.'s TIBCO EBX contains a vulnerability that theoretically allows... |
| CVE-2021-21291 | MEDIUM | 6.1 | 1.4% | Feb 2, 2021 | OAuth2 Proxy is an open-source reverse proxy and static file server that provides authentication using Providers (Google... |
| CVE-2021-21289 | HIGH | 8.3 | 3.5% | Feb 2, 2021 | Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and ... |
| CVE-2021-20199 | MEDIUM | 5.9 | 1.1% | Feb 2, 2021 | Rootless containers run with Podman, receive all traffic with a source IP address of 127.0.0.1 (including from remote ho... |
| CVE-2021-21285 | MEDIUM | 6.5 | 3.3% | Feb 2, 2021 | In Docker before versions 9.03.15, 20.10.3 there is a vulnerability in which pulling an intentionally malformed Docker i... |
| CVE-2021-21284 | MEDIUM | 6.8 | 1.1% | Feb 2, 2021 | In Docker before versions 9.03.15, 20.10.3 there is a vulnerability involving the --userns-remap option in which access ... |
| CVE-2021-25310 | HIGH | 8.8 | 4.6% | Feb 2, 2021 | The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated a... |
| CVE-2021-3281 | MEDIUM | 5.3 | 7.6% | Feb 2, 2021 | In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "... |
| CVE-2021-20207 | — | — | — | Feb 2, 2021 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:CVE-2021-3348. Reason: This candidate is a reservation dup... |
| CVE-2021-3378 | CRITICAL | 9.8 | 97.5% | Feb 1, 2021 | FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl... |
| CVE-2021-3340 | MEDIUM | 6.1 | 0.8% | Feb 1, 2021 | A cross-site scripting (XSS) vulnerability in many forms of Wikindx before 5.7.0 and 6.x through 6.4.0 allows remote att... |
| CVE-2021-21287 | HIGH | 7.7 | 24.8% | Feb 1, 2021 | MinIO is a High Performance Object Storage released under Apache License v2.0. In MinIO before version RELEASE.2021-01-3... |
| CVE-2021-3283 | HIGH | 7.5 | 1.5% | Feb 1, 2021 | HashiCorp Nomad and Nomad Enterprise up to 0.12.9 exec and java task drivers can access processes associated with other ... |
| CVE-2021-3282 | HIGH | 7.5 | 1.3% | Feb 1, 2021 | HashiCorp Vault Enterprise 1.6.0 & 1.6.1 allowed the `remove-peer` raft operator command to be executed against DR secon... |
| CVE-2021-3024 | MEDIUM | 5.3 | 1.4% | Feb 1, 2021 | HashiCorp Vault and Vault Enterprise disclosed the internal IP address of the Vault node when responding to some invalid... |
| CVE-2021-21286 | HIGH | 8.8 | 0.8% | Feb 1, 2021 | AVideo Platform is an open-source Audio and Video platform. It is similar to a self-hosted YouTube. In AVideo Platform b... |
| CVE-2021-23330 | CRITICAL | 9.8 | 5.2% | Feb 1, 2021 | All versions of package launchpad are vulnerable to Command Injection via stop. |
| CVE-2021-21277 | HIGH | 8.8 | 2.7% | Feb 1, 2021 | angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-exp... |
| CVE-2021-21276 | CRITICAL | 9.3 | 7.2% | Feb 1, 2021 | Polr is an open source URL shortener. in Polr before version 2.3.0, a vulnerability in the setup process allows attacker... |
| CVE-2021-21266 | MEDIUM | 5 | 1.1% | Feb 1, 2021 | openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.... |
| CVE-2021-3350 | MEDIUM | 6.1 | 0.8% | Feb 1, 2021 | deleteaccount.php in the Delete Account plugin 1.4 for MyBB allows XSS via the deletereason parameter. |
| CVE-2021-3349 | LOW | 3.3 | 0.3% | Feb 1, 2021 | GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted ke... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now