2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-46203MEDIUM6.5Taocms v3.0.2 was discovered to contain an arbitrary file read vulnerability via the path parameter.
CVE-2021-44299MEDIUM5.4A reflected cross-site scripting (XSS) vulnerability in \lib\packages\themes\themes.php of Navigate CMS v2.9.4 allows au...
CVE-2021-46030MEDIUM5.4There is a Cross Site Scripting attack (XSS) vulnerability in JavaQuarkBBS <= v2. By entering specific statements into t...
CVE-2021-44837MEDIUM4.3An issue was discovered in Delta RM 1.2. It is possible for an unprivileged user to access the same information as an ad...
CVE-2021-35687MEDIUM5.3Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2021-35686MEDIUM4.3Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2021-31821MEDIUM5.5When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which w...
CVE-2021-44839MEDIUM6.5An issue was discovered in Delta RM 1.2. It is possible to request a new password for any other account using the accoun...
CVE-2021-44838MEDIUM4.3An issue was discovered in Delta RM 1.2. Using the /risque/risque/ajax-details endpoint, with a POST request indicating ...
CVE-2021-44836MEDIUM4.3An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking access controls, and it i...
CVE-2021-46005MEDIUM5.4Sourcecodester Car Rental Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via vehicalorcview parameter...
CVE-2021-34406MEDIUM4.7NVIDIA Tegra kernel driver contains a vulnerability in NVHost, where a specific race condition can lead to a null pointe...
CVE-2021-34405MEDIUM5.5NVIDIA Linux distributions contain a vulnerability in TrustZone’s TEE_Malloc function, where an unchecked return value c...
CVE-2021-34402MEDIUM6.7NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to ...
CVE-2021-4074MEDIUM5.4The WHMCS Bridge WordPress plugin is vulnerable to Stored Cross-Site Scripting via the cc_whmcs_bridge_url parameter fou...
CVE-2021-41809MEDIUM4.3SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making qu...
CVE-2021-39946MEDIUM5.4Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowe...
CVE-2021-39942MEDIUM6.5A denial of service vulnerability in GitLab CE/EE affecting all versions starting from 12.0 before 14.3.6, all versions ...
CVE-2021-39927MEDIUM4.3Server side request forgery protections in GitLab CE/EE versions between 8.4 and 14.4.4, between 14.5.0 and 14.5.2, and ...
CVE-2021-39892MEDIUM4.3In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don...
CVE-2021-37867MEDIUM4.3Mattermost Boards plugin v0.10.0 and earlier fails to protect email addresses of all users via one of the Boards APIs, w...
CVE-2021-37865MEDIUM5.7Mattermost 6.2 and earlier fails to sufficiently process a specifically crafted GIF file when it is uploaded while draft...
CVE-2021-37864MEDIUM6.5Mattermost 6.1 and earlier fails to sufficiently validate permissions while viewing archived channels, which allows auth...
CVE-2021-29872MEDIUM5.4IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injec...
CVE-2021-4146MEDIUM4.3Business Logic Errors in GitHub repository pimcore/pimcore prior to 10.2.6.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now