2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24607MEDIUM4.8The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to...
CVE-2021-24594MEDIUM4.8The Translate WordPress – Google Language Translator WordPress plugin before 6.0.12 does not sanitise and escape some of...
CVE-2021-29843MEDIUM6.5IBM MQ 9.1 LTS, 9.1 CD, 9.2 LTS, and 9.2CD is vulnerable to a denial of service attack caused by an issue processing mes...
CVE-2021-29735MEDIUM5.4IBM Security Guardium 10.5, 10.6, 11.0, 11.1, 11.2, and 11.3 is vulnerable to cross-site scripting. This vulnerability a...
CVE-2021-42770MEDIUM6.1A Cross-site scripting (XSS) vulnerability was discovered in OPNsense before 21.7.4 via the LDAP attribute return in the...
CVE-2021-41733MEDIUM6.1Oppia 3.1.4 does not verify that certain URLs are valid before navigating to them.
CVE-2021-37850MEDIUM5.5ESET was made aware of a vulnerability in its consumer and business products for macOS that enables a user logged on to ...
CVE-2021-32483MEDIUM5.3Cloudera Manager 7.2.4 has Incorrect Access Control, allowing Escalation of Privileges to view the restricted Dashboard.
CVE-2021-22051MEDIUM6.5Applications using Spring Cloud Gateway are vulnerable to specifically crafted requests that could make an extra request...
CVE-2021-32482MEDIUM6.1Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS via the path parameter.
CVE-2021-32481MEDIUM6.1Cloudera Hue 4.6.0 allows XSS via the type parameter.
CVE-2021-29994MEDIUM6.1Cloudera Hue 4.6.0 allows XSS.
CVE-2021-29243MEDIUM6.1Cloudera Manager 5.x, 6.x, 7.1.x, 7.2.x, and 7.3.x allows XSS.
CVE-2021-42078MEDIUM6.1PHP Event Calendar through 2021-11-04 allows persistent cross-site scripting (XSS), as demonstrated by the /server/ajax/...
CVE-2021-31601MEDIUM6.5An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The...
CVE-2021-31600MEDIUM4.3An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. The...
CVE-2021-25978MEDIUM5.4Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerable to Stored XSS where an editor uploads an SVG file that co...
CVE-2021-41251MEDIUM5.9@sap-cloud-sdk/core contains the core functionality of the SAP Cloud SDK as well as the SAP Business Technology Platform...
CVE-2021-41250MEDIUM4.3Python discord bot is the community bot for the Python Discord community. In affected versions when a non-blacklisted UR...
CVE-2021-41227MEDIUM5.5TensorFlow is an open source platform for machine learning. In affected versions the `ImmutableConst` operation in Tenso...
CVE-2021-41222MEDIUM5.5TensorFlow is an open source platform for machine learning. In affected versions the implementation of `SplitV` can trig...
CVE-2021-41213MEDIUM5.5TensorFlow is an open source platform for machine learning. In affected versions the code behind `tf.function` API can b...
CVE-2021-41218MEDIUM5.5TensorFlow is an open source platform for machine learning. In affected versions the shape inference code for `AllToAll`...
CVE-2021-41209MEDIUM5.5TensorFlow is an open source platform for machine learning. In affected versions the implementations for convolution ope...
CVE-2021-41207MEDIUM5.5TensorFlow is an open source platform for machine learning. In affected versions the implementation of `ParallelConcat` ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now