2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-3950MEDIUM5.4django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3976MEDIUM6.5kimai2 is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-41532MEDIUM5.3In Apache Ozone before 1.2.0, Recon HTTP endpoints provide access to OM, SCM and Datanode metadata. Due to a bug, any un...
CVE-2021-39235MEDIUM6.5In Apache Ozone before 1.2.0, Ozone Datanode doesn't check the access mode parameter of the block token. Authenticated u...
CVE-2021-39234MEDIUM6.8In Apache Ozone versions prior to 1.2.0, Authenticated users knowing the ID of an existing block can craft specific requ...
CVE-2021-44033MEDIUM6.8In Ionic Identity Vault before 5.0.5, the protection mechanism for invalid unlock attempts can be bypassed.
CVE-2021-44025MEDIUM6.1Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when disp...
CVE-2021-41278MEDIUM5.7Functions SDK for EdgeX is meant to provide all the plumbing necessary for developers to get started in processing/trans...
CVE-2021-40131MEDIUM5.4A vulnerability in the web-based management interface of Cisco Common Services Platform Collector (CSPC) could allow an ...
CVE-2021-40130MEDIUM4.9A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, ...
CVE-2021-40129MEDIUM4.9A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authent...
CVE-2021-43017MEDIUM4.2Adobe Creative Cloud version 5.5 (and earlier) are affected by an Application denial of service vulnerability in the Cre...
CVE-2021-23193MEDIUM6.5Improper privilege validation vulnerability in COM Interface of Gallagher Command Centre Server allows authenticated unp...
CVE-2021-23167MEDIUM6.8Improper certificate validation vulnerability in SMTP Client allows man-in-the-middle attack to retrieve sensitive infor...
CVE-2021-23155MEDIUM6.8Improper validation of the cloud certificate chain in Mobile Client allows man-in-the-middle attack to impersonate the l...
CVE-2021-42268MEDIUM5.5Adobe Animate version 21.0.9 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specia...
CVE-2021-40761MEDIUM5.5Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a ...
CVE-2021-40756MEDIUM5.5Adobe After Effects version 18.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a ...
CVE-2021-43668MEDIUM5.5Go-Ethereum 1.10.9 nodes crash (denial of service) after receiving a serial of messages and cannot be recovered. They wi...
CVE-2021-37938MEDIUM4.3It was discovered that on Windows operating systems specifically, Kibana was not validating a user supplied path, which ...
CVE-2021-43549MEDIUM4.8A remote authenticated attacker with write access to a PI Server could trick a user into interacting with a PI Web API e...
CVE-2021-27026MEDIUM4.4A flaw was divered in Puppet Enterprise and other Puppet products where sensitive plan parameters may be logged
CVE-2021-27025MEDIUM6.5A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Deni...
CVE-2021-0672MEDIUM5.5In Browser app, there is a possible information disclosure due to a missing permission check. This could lead to local i...
CVE-2021-0671MEDIUM6.7In apusys, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of p...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now