2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41792MEDIUM5.3An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-tran...
CVE-2021-41791MEDIUM5.4An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An ev...
CVE-2021-40123MEDIUM6.5A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticat...
CVE-2021-40121MEDIUM4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could al...
CVE-2021-39127MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to the query component JQL e...
CVE-2021-39126MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify various resources via a Cros...
CVE-2021-34789MEDIUM4.8A vulnerability in the web-based management interface of Cisco Tetration could allow an authenticated, remote attacker t...
CVE-2021-34760MEDIUM4.8A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow ...
CVE-2021-34738MEDIUM6.1Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could al...
CVE-2021-42096MEDIUM4.3GNU Mailman before 2.1.35 may allow remote Privilege Escalation. A certain csrf_token value is derived from the admin pa...
CVE-2021-42299MEDIUM5.6Microsoft Surface Pro 3 Security Feature Bypass Vulnerability
CVE-2021-42762MEDIUM5.3BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed...
CVE-2021-38896MEDIUM6.1IBM QRadar Advisor 2.5 through 2.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2021-41135MEDIUM6.5The Cosmos-SDK is a framework for building blockchain applications in Golang. Affected versions of the SDK were vulnerab...
CVE-2021-21745MEDIUM4.3ZTE MF971R product has a Referer authentication bypass vulnerability. Without CSRF verification, an attackercould use th...
CVE-2021-21743MEDIUM4.3ZTE MF971R product has a CRLF injection vulnerability. An attacker could exploit the vulnerability to modify the HTTP re...
CVE-2021-21747MEDIUM6.1ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie informatio...
CVE-2021-21746MEDIUM6.1ZTE MF971R product has reflective XSS vulnerability. An attacker could use the vulnerability to obtain cookie informatio...
CVE-2021-25972MEDIUM4.9In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload fea...
CVE-2021-25971MEDIUM4.3In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes...
CVE-2021-25969MEDIUM6.1In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attack...
CVE-2021-35666MEDIUM5.9Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). The supported vers...
CVE-2021-35665MEDIUM6.1Vulnerability in the Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The supported vers...
CVE-2021-35655MEDIUM5.3Vulnerability in the Essbase Administration Services product of Oracle Essbase (component: EAS Console). The supported v...
CVE-2021-35650MEDIUM4.6Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Client). The supported ve...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now