2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-43575MEDIUM5.5KNX ETS6 through 6.0.0 uses the hard-coded password ETS5Password, with a salt value of Ivan Medvedev, allowing local use...
CVE-2021-35489MEDIUM6.1Thruk 2.40-2 allows /thruk/#cgi-bin/extinfo.cgi?type=2&host={HOSTNAME]&service={SERVICENAME]&backend={BACKEND] Reflected...
CVE-2021-35488MEDIUM6.1Thruk 2.40-2 allows /thruk/#cgi-bin/status.cgi?style=combined&title={TITLE] Reflected XSS via the host or title paramete...
CVE-2021-43181MEDIUM6.1In JetBrains Hub before 2021.1.13690, stored XSS is possible.
CVE-2021-43201MEDIUM5.3In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
CVE-2021-43199MEDIUM5.3In JetBrains TeamCity before 2021.1.2, permission checks in the Create Patch functionality are insufficient.
CVE-2021-43198MEDIUM5.4In JetBrains TeamCity before 2021.1.2, stored XSS is possible.
CVE-2021-43197MEDIUM6.1In JetBrains TeamCity before 2021.1.2, email notifications could include unescaped HTML for XSS.
CVE-2021-43195MEDIUM5.3In JetBrains TeamCity before 2021.1.2, some HTTP security headers were missing.
CVE-2021-43194MEDIUM5.3In JetBrains TeamCity before 2021.1.2, user enumeration was possible.
CVE-2021-43192MEDIUM5.3In JetBrains YouTrack Mobile before 2021.2, iOS URL scheme hijacking is possible.
CVE-2021-43191MEDIUM5.3JetBrains YouTrack Mobile before 2021.2, is missing the security screen on Android and iOS.
CVE-2021-43190MEDIUM5.3In JetBrains YouTrack Mobile before 2021.2, task hijacking on Android is possible.
CVE-2021-43187MEDIUM5.3In JetBrains YouTrack Mobile before 2021.2, the client-side cache on iOS could contain sensitive information.
CVE-2021-43186MEDIUM5.4JetBrains YouTrack before 2021.3.24402 is vulnerable to stored XSS.
CVE-2021-43184MEDIUM5.4In JetBrains YouTrack before 2021.3.21051, stored XSS is possible.
CVE-2021-3641MEDIUM6.1Improper Link Resolution Before File Access ('Link Following') vulnerability in the EPAG component of Bitdefender Endpoi...
CVE-2021-43519MEDIUM5.5Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via...
CVE-2021-42026MEDIUM4.3A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications...
CVE-2021-42025MEDIUM6.5A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications...
CVE-2021-42015MEDIUM5.5A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications...
CVE-2021-40364MEDIUM5.5A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3 UC...
CVE-2021-31344MEDIUM5.3A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R...
CVE-2021-40261MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester CASAP Automated Enrollment System 1.0 via th...
CVE-2021-40260MEDIUM6.1Multiple Cross Site Scripting (XSS) vulnerabilities exist in SourceCodester Tailor Management 1.0 via the (1) eid parame...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now