2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29771MEDIUM5.4IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed a...
CVE-2021-29738MEDIUM5.4IBM InfoSphere Data Flow Designer (IBM InfoSphere Information Server 11.7 ) is vulnerable to server-side request forgery...
CVE-2021-42568MEDIUM4.3Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function vi...
CVE-2021-27722MEDIUM5.5An issue was discovered in Nsasoft US LLC SpotAuditor 5.3.5. The program can be crashed by entering 300 bytes char data ...
CVE-2021-33611MEDIUM6.1Missing output sanitization in test sources in org.webjars.bowergithub.vaadin:vaadin-menu-bar versions 1.0.0 through 1.2...
CVE-2021-33593MEDIUM5.3Whale browser for iOS before 1.14.0 has an inconsistent user interface issue that allows an attacker to obfuscate the ad...
CVE-2021-25973MEDIUM6.5In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper Access Control. “guest” role users can self-register even whe...
CVE-2021-41310MEDIUM6.1Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to inject arbitrary HTML or ...
CVE-2021-43058MEDIUM6.1An open redirect vulnerability exists in Replicated Classic versions prior to 2.53.1 that could lead to spoofing. To exp...
CVE-2021-39346MEDIUM4.8The Google Maps Easy WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation ...
CVE-2021-39340MEDIUM4.8The Notification WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and ...
CVE-2021-38356MEDIUM6.1The NextScripts: Social Networks Auto-Poster <= 4.3.20 WordPress plugin is vulnerable to Reflected Cross-Site Scripting ...
CVE-2021-31848MEDIUM6.1Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a r...
CVE-2021-42917MEDIUM5.5Buffer overflow vulnerability in Kodi xbmc up to 19.0, allows attackers to cause a denial of service due to improper len...
CVE-2021-29213MEDIUM6.7A potential local bypass of security restrictions vulnerability has been identified in HPE ProLiant DL20 Gen10, HPE ProL...
CVE-2021-27004MEDIUM5.5System Manager 9.x versions 9.7 and higher prior to 9.7P16, 9.8P7 and 9.9.1P2 are susceptible to a vulnerability which c...
CVE-2021-22564MEDIUM5.5For certain valid JPEG XL images with a size slightly larger than an integer number of groups (256x256 pixels) when proc...
CVE-2021-22563MEDIUM4.4Invalid JPEG XL images using libjxl can cause an out of bounds access on a std::vector<std::vector<T>> when rendering sp...
CVE-2021-25878MEDIUM6.1AVideo/YouPHPTube 10.0 and prior is affected by multiple reflected Cross Script Scripting vulnerabilities via the videoN...
CVE-2021-25876MEDIUM6.1AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the u parameter which...
CVE-2021-25875MEDIUM6.1AVideo/YouPHPTube AVideo/YouPHPTube 10.0 and prior has multiple reflected Cross Script Scripting vulnerabilities via the...
CVE-2021-41973MEDIUM6.5In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. T...
CVE-2021-24813MEDIUM4.8The Events Made Easy WordPress plugin before 2.2.24 does not sanitise and escape Custom Field Names, allowing high privi...
CVE-2021-24808MEDIUM6.1The BP Better Messages WordPress plugin before 1.9.9.41 sanitise (with sanitize_text_field) but does not escape the 'sub...
CVE-2021-24799MEDIUM4.3The Far Future Expiry Header WordPress plugin before 1.5 does not have CSRF check when saving its settings, which could ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now