2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41142 | MEDIUM | 5.4 | 0.7% | Oct 14, 2021 | Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Ther... |
| CVE-2021-41132 | MEDIUM | 6.1 | 1.0% | Oct 14, 2021 | OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do ... |
| CVE-2021-38345 | MEDIUM | 6.5 | 0.7% | Oct 14, 2021 | The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in u... |
| CVE-2021-38344 | MEDIUM | 5.4 | 0.6% | Oct 14, 2021 | The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a s... |
| CVE-2021-33179 | MEDIUM | 6.1 | 4.3% | Oct 14, 2021 | The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scri... |
| CVE-2021-33178 | MEDIUM | 6.5 | 1.8% | Oct 14, 2021 | The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path trave... |
| CVE-2021-22963 | MEDIUM | 6.1 | 1.1% | Oct 14, 2021 | A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbit... |
| CVE-2021-3882 | MEDIUM | 6.8 | 0.9% | Oct 14, 2021 | LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the Led... |
| CVE-2021-26318 | MEDIUM | 4.7 | 0.3% | Oct 13, 2021 | A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially... |
| CVE-2021-42223 | MEDIUM | 6.1 | 0.8% | Oct 13, 2021 | Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php. |
| CVE-2021-41139 | MEDIUM | 6.1 | 1.0% | Oct 13, 2021 | Anuko Time Tracker is an open source, web-based time tracking application written in PHP. When a logged on user selects ... |
| CVE-2021-40732 | MEDIUM | 6.1 | 2.3% | Oct 13, 2021 | XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in le... |
| CVE-2021-41138 | MEDIUM | 5.3 | 1.3% | Oct 13, 2021 | Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pa... |
| CVE-2021-22036 | MEDIUM | 6.5 | 0.9% | Oct 13, 2021 | VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. ... |
| CVE-2021-22035 | MEDIUM | 4.3 | 0.6% | Oct 13, 2021 | VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interact... |
| CVE-2021-20128 | MEDIUM | 5.4 | 0.6% | Oct 13, 2021 | The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable... |
| CVE-2021-33609 | MEDIUM | 4.3 | 0.9% | Oct 13, 2021 | Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through ... |
| CVE-2021-20834 | MEDIUM | 6.1 | 1.2% | Oct 13, 2021 | Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 an... |
| CVE-2021-20832 | MEDIUM | 5.3 | 0.8% | Oct 13, 2021 | InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerabi... |
| CVE-2021-20807 | MEDIUM | 6.1 | 0.7% | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote atta... |
| CVE-2021-20806 | MEDIUM | 6.1 | 0.8% | Oct 13, 2021 | Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitra... |
| CVE-2021-20805 | MEDIUM | 5.4 | 0.6% | Oct 13, 2021 | Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote auth... |
| CVE-2021-20804 | MEDIUM | 6.5 | 1.1% | Oct 13, 2021 | Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition... |
| CVE-2021-20803 | MEDIUM | 5.4 | 0.7% | Oct 13, 2021 | Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authentica... |
| CVE-2021-20802 | MEDIUM | 5.3 | 1.0% | Oct 13, 2021 | HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the inform... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now