2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41951 | MEDIUM | 6.1 | 77.9% | Nov 15, 2021 | ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_ss... |
| CVE-2021-38982 | MEDIUM | 5.4 | 0.5% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allo... |
| CVE-2021-38981 | MEDIUM | 5.3 | 1.3% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information ... |
| CVE-2021-38978 | MEDIUM | 5.9 | 0.9% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information,... |
| CVE-2021-38977 | MEDIUM | 4.3 | 0.5% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or s... |
| CVE-2021-38976 | MEDIUM | 5.5 | 0.2% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read ... |
| CVE-2021-38975 | MEDIUM | 6.5 | 0.9% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive infor... |
| CVE-2021-38974 | MEDIUM | 6.5 | 1.0% | Nov 15, 2021 | IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service... |
| CVE-2021-43574 | MEDIUM | 6.1 | 2.4% | Nov 15, 2021 | WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default U... |
| CVE-2021-42703 | MEDIUM | 6.1 | 0.6% | Nov 15, 2021 | This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie... |
| CVE-2021-22959 | MEDIUM | 6.5 | 2.9% | Nov 15, 2021 | The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Req... |
| CVE-2021-42838 | MEDIUM | 6.1 | 0.6% | Nov 15, 2021 | Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thu... |
| CVE-2021-41289 | MEDIUM | 6.3 | 0.2% | Nov 15, 2021 | ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a g... |
| CVE-2021-3915 | MEDIUM | 5.7 | 0.9% | Nov 13, 2021 | bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type |
| CVE-2021-3776 | MEDIUM | 5.4 | 0.4% | Nov 13, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3775 | MEDIUM | 5.4 | 0.4% | Nov 13, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3683 | MEDIUM | 6.5 | 0.4% | Nov 13, 2021 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3945 | MEDIUM | 6.1 | 1.0% | Nov 13, 2021 | django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3938 | MEDIUM | 5.4 | 0.5% | Nov 13, 2021 | snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-3932 | MEDIUM | 4.3 | 0.4% | Nov 13, 2021 | twill is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3931 | MEDIUM | 4.3 | 0.4% | Nov 13, 2021 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-3921 | MEDIUM | 4.3 | 0.4% | Nov 13, 2021 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2021-34357 | MEDIUM | 6.1 | 0.7% | Nov 13, 2021 | A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, thi... |
| CVE-2021-41229 | MEDIUM | 6.5 | 1.1% | Nov 12, 2021 | BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which... |
| CVE-2021-36325 | MEDIUM | 6.7 | 0.2% | Nov 12, 2021 | Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now