2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-27836MEDIUM6.5An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial o...
CVE-2021-43324MEDIUM6.1LibreNMS through 21.10.2 allows XSS via a widget title.
CVE-2021-36698MEDIUM5.4Pandora FMS through 755 allows XSS via a new Event Filter with a crafted name.
CVE-2021-36697MEDIUM6.7With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component...
CVE-2021-33209MEDIUM5.3An issue was discovered in Fimer Aurora Vision before 2.97.10. The response to a failed login attempt discloses whether ...
CVE-2021-33210MEDIUM4.3An issue was discovered in Fimer Aurora Vision before 2.97.10. An attacker can (in the WebUI) obtain plant information w...
CVE-2021-39237MEDIUM4.6Certain HP LaserJet, HP LaserJet Managed, HP PageWide, and HP PageWide Managed printers may be vulnerable to potential i...
CVE-2021-38502MEDIUM5.9Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgr...
CVE-2021-38497MEDIUM6.5Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another o...
CVE-2021-38492MEDIUM6.5When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to...
CVE-2021-38491MEDIUM6.5Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerabil...
CVE-2021-20135MEDIUM6.7Nessus versions 8.15.2 and earlier were found to contain a local privilege escalation vulnerability which could allow an...
CVE-2021-43265MEDIUM5.4In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, certain tag syntax could be used for XSS, such as via a SCRIPT ...
CVE-2021-37996MEDIUM5.5Insufficient validation of untrusted input Downloads in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to...
CVE-2021-37995MEDIUM6.5Inappropriate implementation in WebApp Installer in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to pot...
CVE-2021-37994MEDIUM6.5Inappropriate implementation in iFrame Sandbox in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to bypas...
CVE-2021-37990MEDIUM5.5Inappropriate implementation in WebView in Google Chrome on Android prior to 95.0.4638.54 allowed a remote attacker to l...
CVE-2021-37989MEDIUM6.5Inappropriate implementation in Blink in Google Chrome prior to 95.0.4638.54 allowed a remote attacker to abuse content ...
CVE-2021-42754MEDIUM5An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 ...
CVE-2021-41023MEDIUM5.5A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated...
CVE-2021-36184MEDIUM6.5A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6....
CVE-2021-36176MEDIUM6.1Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a ...
CVE-2021-41019MEDIUM6.5An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may...
CVE-2021-32595MEDIUM6.5Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a ...
CVE-2021-26107MEDIUM4.3An improper access control vulnerability [CWE-284] in FortiManager versions 6.4.4 and 6.4.5 may allow an authenticated a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now