2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36739MEDIUM6.1The "first name" and "last name" fields of the Apache Pluto 3.1.0 MVCBean JSP portlet maven archetype are vulnerable to ...
CVE-2021-36738MEDIUM6.1The input fields in the JSP version of the Apache Pluto Applicant MVCBean CDI portlet are vulnerable to Cross-Site Scrip...
CVE-2021-36737MEDIUM6.1The input fields of the Apache Pluto UrlTestPortlet are vulnerable to Cross-Site Scripting (XSS) attacks. Users should m...
CVE-2021-46145MEDIUM5.3The keyfob subsystem in Honda Civic 2012 vehicles allows a replay attack for unlocking. This is related to a non-expirin...
CVE-2021-46144MEDIUM6.1Roundcube before 1.4.13 and 1.5.x before 1.5.2 allows XSS via an HTML e-mail message with crafted Cascading Style Sheets...
CVE-2021-46142MEDIUM5.5An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
CVE-2021-46141MEDIUM5.5An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeO...
CVE-2021-46038MEDIUM5.5A Pointer Dereference vulnerability exists in GPAC 1.0.1 in unlink_chunk.isra, which causes a Denial of Service (context...
CVE-2021-45833MEDIUM5.5A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 via the H5D__create_chunk_file_map_hyper function in...
CVE-2021-45832MEDIUM5.5A Stack-based Buffer Overflow Vulnerability exists in HDF5 1.13.1-1 at at hdf5/src/H5Eint.c, which causes a Denial of Se...
CVE-2021-45831MEDIUM5.5A Null Pointer Dereference vulnerability exitgs in GPAC 1.0.1 in MP4Box via __strlen_avx2, which causes a Denial of Serv...
CVE-2021-45830MEDIUM5.5A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which ...
CVE-2021-28713MEDIUM6.5Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; ...
CVE-2021-28712MEDIUM6.5Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; ...
CVE-2021-28711MEDIUM6.5Rogue backends can cause DoS of guests via high frequency events T[his CNA information record relates to multiple CVEs; ...
CVE-2021-41043MEDIUM5.5Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact.
CVE-2021-31589MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported and confirmed for BeyondTrust Secure Remote Access Base Sof...
CVE-2021-43946MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow authenticated remote attackers to add administrator gro...
CVE-2021-45452MEDIUM5.3Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted ...
CVE-2021-43850MEDIUM6.8Discourse is an open source platform for community discussion. In affected versions admins users can trigger a Denial of...
CVE-2021-43677MEDIUM6.1Fluxbb v1.4.12 is affected by a Cross Site Scripting (XSS) vulnerability.
CVE-2021-41236MEDIUM4.8OroPlatform is a PHP Business Application Platform. In affected versions the email template preview is vulnerable to XSS...
CVE-2021-41789MEDIUM6.5In wifi driver, there is a possible system crash due to a missing validation check. This could lead to remote denial of ...
CVE-2021-40111MEDIUM6.5In Apache James, while fuzzing with Jazzer the IMAP parsing stack, we discover that crafted APPEND and STATUS IMAP comma...
CVE-2021-38542MEDIUM5.9Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now