2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-45516MEDIUM4.5Certain NETGEAR devices are affected by denial of service. This affects R6400 before 1.0.1.70, R7000 before 1.0.11.126, ...
CVE-2021-45515MEDIUM6.5Certain NETGEAR devices are affected by denial of service. This affects EX7500 before 1.0.0.72, RBS40V before 2.6.1.4, R...
CVE-2021-45494MEDIUM4.5Certain NETGEAR devices are affected by an attacker's ability to read arbitrary files. This affects RBK352 before 4.4.0....
CVE-2021-4162MEDIUM4.3archivy is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-45483MEDIUM6.5In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::Frame::page, a different vulnerability than CVE-2021-3...
CVE-2021-45482MEDIUM6.5In WebKitGTK before 2.32.4, there is a use-after-free in WebCore::ContainerNode::firstChild, a different vulnerability t...
CVE-2021-45481MEDIUM6.5In WebKitGTK before 2.32.4, there is incorrect memory allocation in WebCore::ImageBufferCairoImageSurfaceBackend::create...
CVE-2021-45480MEDIUM5.5An issue was discovered in the Linux kernel before 5.15.11. There is a memory leak in the __rds_conn_create() function i...
CVE-2021-3977MEDIUM5.4invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-4072MEDIUM5.4elgg is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-20876MEDIUM6.8Path traversal vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlie...
CVE-2021-20875MEDIUM6.1Open redirect vulnerability in GroupSession Free edition ver5.1.1 and earlier, GroupSession byCloud ver5.1.1 and earlier...
CVE-2021-45474MEDIUM6.1In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl pa...
CVE-2021-45473MEDIUM6.1In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (...
CVE-2021-45472MEDIUM6.1In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that ...
CVE-2021-45471MEDIUM5.3In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items.
CVE-2021-3622MEDIUM4.3A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive)...
CVE-2021-4024MEDIUM6.5A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a...
CVE-2021-44543MEDIUM6.1An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Pr...
CVE-2021-30767MEDIUM5.5A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.6.2, macOS Monterey ...
CVE-2021-27006MEDIUM4.4StorageGRID (formerly StorageGRID Webscale) versions 11.5 prior to 11.5.0.5 are susceptible to a vulnerability which may...
CVE-2021-43849MEDIUM5.5cordova-plugin-fingerprint-aio is a plugin provides a single and simple interface for accessing fingerprint APIs on both...
CVE-2021-4068MEDIUM6.5Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cr...
CVE-2021-4059MEDIUM6.5Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-or...
CVE-2021-4054MEDIUM6.5Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spo...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now