2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41951MEDIUM6.1ResourceSpace before 9.6 rev 18290 is affected by a reflected Cross-Site Scripting vulnerability in plugins/wordpress_ss...
CVE-2021-38982MEDIUM5.4IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 is vulnerable to cross-site scripting. This vulnerability allo...
CVE-2021-38981MEDIUM5.3IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information ...
CVE-2021-38978MEDIUM5.9IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow a remote attacker to obtain sensitive information,...
CVE-2021-38977MEDIUM4.3IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 does not set the secure attribute on authorization tokens or s...
CVE-2021-38976MEDIUM5.5IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 stores user credentials in plain clear text which can be read ...
CVE-2021-38975MEDIUM6.5IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive infor...
CVE-2021-38974MEDIUM6.5IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to cause a denial of service...
CVE-2021-43574MEDIUM6.1WebAdmin Control Panel in Atmail 6.5.0 (a version released in 2012) allows XSS via the format parameter to the default U...
CVE-2021-42703MEDIUM6.1This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie...
CVE-2021-22959MEDIUM6.5The parser in accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Req...
CVE-2021-42838MEDIUM6.1Grand Vice info Co. webopac7 book search field parameter does not properly restrict the input of special characters, thu...
CVE-2021-41289MEDIUM6.3ASUS P453UJ contains the Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability. With a g...
CVE-2021-3915MEDIUM5.7bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
CVE-2021-3776MEDIUM5.4showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3775MEDIUM5.4showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3683MEDIUM6.5showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3945MEDIUM6.1django-helpdesk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3938MEDIUM5.4snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3932MEDIUM4.3twill is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3931MEDIUM4.3snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-3921MEDIUM4.3firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF)
CVE-2021-34357MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running QmailAgent. If exploited, thi...
CVE-2021-41229MEDIUM6.5BlueZ is a Bluetooth protocol stack for Linux. In affected versions a vulnerability exists in sdp_cstate_alloc_buf which...
CVE-2021-36325MEDIUM6.7Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially expl...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now