2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-43436MEDIUM5.4MartDevelopers Inc iResturant v1.0 allows Stored XSS by placing a payload in the username field during a login attempt. ...
CVE-2021-44649MEDIUM5.4Django CMS 3.7.3 does not validate the plugin_type parameter while generating error messages for an invalid plugin type,...
CVE-2021-46283MEDIUM5.5nf_tables_newset in net/netfilter/nf_tables_api.c in the Linux kernel before 5.12.13 allows local users to cause a denia...
CVE-2021-41767MEDIUM6.5Apache Guacamole 1.3.0 and older may incorrectly include a private tunnel identifier in the non-private details of some ...
CVE-2021-43974MEDIUM5.3An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, ...
CVE-2021-43972MEDIUM6.5An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authe...
CVE-2021-29701MEDIUM4.3IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could a...
CVE-2021-44647MEDIUM5.5Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a l...
CVE-2021-37196MEDIUM6.5A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers...
CVE-2021-37195MEDIUM6.1A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used), COMOS V10.3 (All vers...
CVE-2021-36411MEDIUM5.5An issue has been found in libde265 v1.0.8 due to incorrect access control. A SEGV caused by a READ memory access in fun...
CVE-2021-36410MEDIUM5.5A stack-buffer-overflow exists in libde265 v1.0.8 via fallback-motion.cc in function put_epel_hv_fallback when running p...
CVE-2021-36408MEDIUM5.5An issue was discovered in libde265 v1.0.8.There is a Heap-use-after-free in intrapred.h when decoding file using dec265...
CVE-2021-35452MEDIUM6.5An Incorrect Access Control vulnerability exists in libde265 v1.0.8 due to a SEGV in slice.cc.
CVE-2021-43951MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi...
CVE-2021-43949MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi...
CVE-2021-25047MEDIUM6.1The 10Web Social Photo Feed WordPress plugin before 1.4.29 was affected by a reflected Cross-Site Scripting (XSS) vulner...
CVE-2021-25043MEDIUM6.1The WOOCS WordPress plugin before 1.3.7.3 does not sanitise and escape the custom_prices parameter before outputting it ...
CVE-2021-46166MEDIUM6.5Zoho ManageEngine Desktop Central before 10.0.662 allows authenticated users to obtain sensitive information from the da...
CVE-2021-46163MEDIUM6.1Kentico Xperience 13.0.44 allows XSS via an XML document to the Media Libraries subsystem.
CVE-2021-46150MEDIUM4.8An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Special:CheckUserLog...
CVE-2021-46148MEDIUM6.5An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. Some unprivileged us...
CVE-2021-46146MEDIUM5.4An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The WikibaseMediaInf...
CVE-2021-46055MEDIUM5.5A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitReth...
CVE-2021-46054MEDIUM5.5A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitReth...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now