2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-0893MEDIUM6.7In apusys, there is a possible memory corruption due to a use after free. This could lead to local escalation of privile...
CVE-2021-0679MEDIUM6.7In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of p...
CVE-2021-0678MEDIUM6.7In apusys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of...
CVE-2021-0677MEDIUM4.4In ccu driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information d...
CVE-2021-0676MEDIUM4.4In geniezone driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local i...
CVE-2021-0674MEDIUM5.5In alac decoder, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local infor...
CVE-2021-45042MEDIUM4.9In HashiCorp Vault and Vault Enterprise before 1.7.7, 1.8.x before 1.8.6, and 1.9.x before 1.9.1, clusters using the Int...
CVE-2021-42584MEDIUM5.4A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32.
CVE-2021-4132MEDIUM5.4livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-43678MEDIUM6.1Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.
CVE-2021-44145MEDIUM6.5In the TransformXML processor of Apache NiFi before 1.15.1 an authenticated user could configure an XSLT file which, if ...
CVE-2021-45038MEDIUM5.3An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=r...
CVE-2021-44857MEDIUM6.5An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to us...
CVE-2021-41843MEDIUM6.5An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker ...
CVE-2021-3179MEDIUM5.5GGLocker iOS application, contains an insecure data storage of the password hash value which results in an authenticatio...
CVE-2021-26800MEDIUM6.5Cross Site Request Forgery (CSRF) vulnerability in Change-password.php in phpgurukul user management system in php using...
CVE-2021-44317MEDIUM5.4In Bus Pass Management System v1.0, parameters 'pagedes' and `About Us` are affected with a Stored Cross-site scripting ...
CVE-2021-43812MEDIUM6.1The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before 1.6.2 d...
CVE-2021-42550MEDIUM6.6In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could...
CVE-2021-41261MEDIUM4.8Galette is a membership management web application built for non profit organizations and released under GPLv3. Versions...
CVE-2021-41962MEDIUM4.8Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Vehicle Service Management System 1.0 via the Owner fu...
CVE-2021-4124MEDIUM6.1janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-40835MEDIUM4.3An URL Address bar spoofing vulnerability was discovered in Safe Browser for iOS. When user clicks on a specially crafte...
CVE-2021-4123MEDIUM6.5livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-4121MEDIUM6.1yetiforcecrm is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now