2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41142MEDIUM5.4Tuleap Open ALM is a libre and open source tool for end to end traceability of application and system developments. Ther...
CVE-2021-41132MEDIUM6.1OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do ...
CVE-2021-38345MEDIUM6.5The Brizy Page Builder plugin <= 2.3.11 for WordPress used an incorrect authorization check that allowed any logged-in u...
CVE-2021-38344MEDIUM5.4The Brizy Page Builder plugin <= 2.3.11 for WordPress was vulnerable to stored XSS by lower-privileged users such as a s...
CVE-2021-33179MEDIUM6.1The general user interface in Nagios XI versions prior to 5.8.4 is vulnerable to authenticated reflected cross-site scri...
CVE-2021-33178MEDIUM6.5The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path trave...
CVE-2021-22963MEDIUM6.1A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbit...
CVE-2021-3882MEDIUM6.8LedgerSMB does not set the 'Secure' attribute on the session authorization cookie when the client uses HTTPS and the Led...
CVE-2021-26318MEDIUM4.7A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially...
CVE-2021-42223MEDIUM6.1Cross Site Scripting (XSS).vulnerability exists in Online DJ Booking Management System 1.0 in view-booking-detail.php.
CVE-2021-41139MEDIUM6.1Anuko Time Tracker is an open source, web-based time tracking application written in PHP. When a logged on user selects ...
CVE-2021-40732MEDIUM6.1XMP Toolkit version 2020.1 (and earlier) is affected by a null pointer dereference vulnerability that could result in le...
CVE-2021-41138MEDIUM5.3Frontier is Substrate's Ethereum compatibility layer. In the newly introduced signed Frontier-specific extrinsic for `pa...
CVE-2021-22036MEDIUM6.5VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. ...
CVE-2021-22035MEDIUM4.3VMware vRealize Log Insight (8.x prior to 8.6) contains a CSV(Comma Separated Value) injection vulnerability in interact...
CVE-2021-20128MEDIUM5.4The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable...
CVE-2021-33609MEDIUM4.3Missing check in DataCommunicator class in com.vaadin:vaadin-server versions 8.0.0 through 8.14.0 (Vaadin 8.0.0 through ...
CVE-2021-20834MEDIUM6.1Improper authorization in handler for custom URL scheme vulnerability in Nike App for Android versions prior to 2.177 an...
CVE-2021-20832MEDIUM5.3InBody App for iOS versions prior to 2.3.30 and InBody App for Android versions prior to 2.2.90(510) contain a vulnerabi...
CVE-2021-20807MEDIUM6.1Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.0.0 to 3.1.9 allows a remote atta...
CVE-2021-20806MEDIUM6.1Open redirect vulnerability in Cybozu Remote Service 3.0.0 to 3.1.9 allows remote attackers to redirect users to arbitra...
CVE-2021-20805MEDIUM5.4Cross-site scripting vulnerability in the management screen of Cybozu Remote Service 3.1.7 to 3.1.9 allows a remote auth...
CVE-2021-20804MEDIUM6.5Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to cause a denial of service (DoS) condition...
CVE-2021-20803MEDIUM5.4Operation restriction bypass in the management screen of Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authentica...
CVE-2021-20802MEDIUM5.3HTTP header injection vulnerability in Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote attacker to alter the inform...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now