2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-46336MEDIUM5.5There is an Assertion 'opts & PARSER_CLASS_LITERAL_CTOR_PRESENT' failed at /parser/js/js-parser-expr.c(parser_parse_clas...
CVE-2021-46335MEDIUM5.5Moddable SDK v11.5.0 was discovered to contain a NULL pointer dereference in the component fx_Function_prototype_hasInst...
CVE-2021-46333MEDIUM5.5Moddable SDK v11.5.0 was discovered to contain an invalid memory access vulnerability via the component __asan_memmove.
CVE-2021-46331MEDIUM5.5Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsProxy.c in fxProxyGetPrototype.
CVE-2021-46330MEDIUM5.5Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsDataView.c in fx_ArrayBuffer_protot...
CVE-2021-46329MEDIUM5.5Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via the component _fini.
CVE-2021-46327MEDIUM5.5Moddable SDK v11.5.0 was discovered to contain a SEGV vulnerability via xs/sources/xsArray.c in fx_Array_prototype_sort.
CVE-2021-46323MEDIUM5.5Espruino 2v11.251 was discovered to contain a SEGV vulnerability via src/jsinteractive.c in jsiGetDeviceFromClass.
CVE-2021-46322MEDIUM5.5Duktape v2.99.99 was discovered to contain a SEGV vulnerability via the component duk_push_tval in duktape/duk_api_stack...
CVE-2021-29785MEDIUM5.9IBM Security SOAR V42 and V43could allow a remote attacker to obtain sensitive information, caused by the failure to pro...
CVE-2021-44091MEDIUM5.4A Cross-Site Scripting (XSS) vulnerability exists in Courcecodester Multi Restaurant Table Reservation System 1.0 in reg...
CVE-2021-44829MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in index.html in AFI WebACMS through 2.1.0 via the the ID parameter.
CVE-2021-32039MEDIUM5.5Users with appropriate file access may be able to access unencrypted user credentials saved by MongoDB Extension for VS ...
CVE-2021-34600MEDIUM5.5Telenot CompasX versions prior to 32.0 use a weak seed for random number generation leading to predictable AES keys used...
CVE-2021-45230MEDIUM6.5In Apache Airflow prior to 2.2.0. This CVE applies to a specific case where a User who has "can_create" permissions on D...
CVE-2021-3866MEDIUM5.4Cross-site Scripting (XSS) - Stored in GitHub repository zulip/zulip more than and including 44f935695d452cc3fb16845a0c6...
CVE-2021-46028MEDIUM4.3In mblog <= 3.5.0 there is a CSRF vulnerability in the background article management. The attacker constructs a CSRF loa...
CVE-2021-46026MEDIUM5.4mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag...
CVE-2021-4143MEDIUM6.1Cross-site Scripting (XSS) - Generic in GitHub repository bigbluebutton/bigbluebutton prior to 2.4.0.
CVE-2021-46027MEDIUM6.5mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSR...
CVE-2021-46025MEDIUM5.4A Cross SIte Scripting (XSS) vulnerability exists in OneBlog <= 2.2.8. via the add function in the operation tab list in...
CVE-2021-44777MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerabilities leading to single or bulk e-mail entries deletion discovered in Email ...
CVE-2021-3816MEDIUM5.4Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary HTML in the group_prefix fi...
CVE-2021-26247MEDIUM6.1As an unauthenticated remote user, visit "http://<CACTI_SERVER>/auth_changepassword.php?ref=<script>alert(1)</script>" t...
CVE-2021-23225MEDIUM5.4Cacti 1.1.38 allows authenticated users with User Management permissions to inject arbitrary web script or HTML in the "...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now