2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-30845MEDIUM5.5An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.6. A local us...
CVE-2021-30828MEDIUM5.5This issue was addressed with improved checks. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 1...
CVE-2021-30819MEDIUM5.5An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 15 and iPadOS 15. Process...
CVE-2021-30811MEDIUM5.5This issue was addressed with improved checks. This issue is fixed in iOS 15 and iPadOS 15, watchOS 8. A local attacker ...
CVE-2021-30810MEDIUM4.3An authorization issue was addressed with improved state management. This issue is fixed in iOS 15 and iPadOS 15, watchO...
CVE-2021-3879MEDIUM5.4snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3863MEDIUM6.1snipe-it is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-3851MEDIUM5.4firefly-iii is vulnerable to URL Redirection to Untrusted Site
CVE-2021-38482MEDIUM4.8InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 website used to control the router is vulnerable to ...
CVE-2021-38476MEDIUM5.3InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 authentication process response indicates and valida...
CVE-2021-38472MEDIUM4.7InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not contain an X-FRAME-OPTION...
CVE-2021-38468MEDIUM4.8InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to stored cross-scripting, which may ...
CVE-2021-38466MEDIUM6.1InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 do not perform sufficient input validation on client...
CVE-2021-25968MEDIUM5.4In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a stored XSS vulnerability that allows low privileged applicatio...
CVE-2021-20836MEDIUM6.5Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privile...
CVE-2021-42650MEDIUM6.1Cross Site Scripting (XSS vulnerability exists in Portainer before 2.9.1 via the node input box in Custom Templates.
CVE-2021-41156MEDIUM5.4anuko/timetracker is an, open source time tracking system. In affected versions Time Tracker uses browser_today hidden c...
CVE-2021-41151MEDIUM4.9Backstage is an open platform for building developer portals. In affected versions A malicious actor could read sensitiv...
CVE-2021-42055MEDIUM6.8ASUSTek ZenBook Pro Due 15 UX582 laptop firmware through 203 has Insecure Permissions that allow attacks by a physically...
CVE-2021-29878MEDIUM5.4IBM Business Automation Workflow 18.0, 19.0, 20.0, and 21.0 is vulnerable to cross-site scripting. This vulnerability al...
CVE-2021-32609MEDIUM5.4Apache Superset up to and including 1.1 does not sanitize titles correctly on the Explore page. This allows an attacker ...
CVE-2021-24760MEDIUM5.4The Gutenberg PDF Viewer Block WordPress plugin before 1.0.1 does not sanitise and escape its block, which could allow u...
CVE-2021-24752MEDIUM5.7Multiple Plugins from the CatchThemes vendor do not perform capability and CSRF checks in the ctp_switch AJAX action, wh...
CVE-2021-24743MEDIUM5.4The Podcast Subscribe Buttons WordPress plugin before 1.4.2 allows users with any role capable of editing or adding post...
CVE-2021-24740MEDIUM4.8The Tutor LMS WordPress plugin before 1.9.9 does not escape some of its settings before outputting them in attributes, w...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now