2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-35060 | MEDIUM | 5.3 | 0.8% | Oct 11, 2021 | /way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response difference... |
| CVE-2021-35059 | MEDIUM | 6.1 | 0.6% | Oct 11, 2021 | OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter. |
| CVE-2021-41831 | MEDIUM | 5.3 | 1.5% | Oct 11, 2021 | It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to ... |
| CVE-2021-41800 | MEDIUM | 5.3 | 1.7% | Oct 11, 2021 | MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visi... |
| CVE-2021-41798 | MEDIUM | 6.1 | 1.3% | Oct 11, 2021 | MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Se... |
| CVE-2021-42137 | MEDIUM | 5.3 | 0.8% | Oct 11, 2021 | An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requiremen... |
| CVE-2021-42134 | MEDIUM | 6.1 | 0.7% | Oct 11, 2021 | The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incompl... |
| CVE-2021-37976 | MEDIUM | 6.5 | 19.9% | Oct 8, 2021 | Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potent... |
| CVE-2021-37971 | MEDIUM | 4.3 | 1.2% | Oct 8, 2021 | Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the co... |
| CVE-2021-37968 | MEDIUM | 4.3 | 1.2% | Oct 8, 2021 | Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to... |
| CVE-2021-37967 | MEDIUM | 4.3 | 0.8% | Oct 8, 2021 | Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker wh... |
| CVE-2021-37966 | MEDIUM | 4.3 | 0.7% | Oct 8, 2021 | Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker ... |
| CVE-2021-37965 | MEDIUM | 4.3 | 1.1% | Oct 8, 2021 | Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to... |
| CVE-2021-37963 | MEDIUM | 4.3 | 1.1% | Oct 8, 2021 | Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass ... |
| CVE-2021-37958 | MEDIUM | 5.4 | 0.9% | Oct 8, 2021 | Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker t... |
| CVE-2021-42112 | MEDIUM | 6.1 | 1.5% | Oct 8, 2021 | The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog.... |
| CVE-2021-30630 | MEDIUM | 4.3 | 0.7% | Oct 8, 2021 | Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromis... |
| CVE-2021-29906 | MEDIUM | 5.5 | 0.2% | Oct 8, 2021 | IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a... |
| CVE-2021-41802 | MEDIUM | 5.4 | 0.6% | Oct 8, 2021 | HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID ... |
| CVE-2021-32029 | MEDIUM | 6.5 | 1.4% | Oct 8, 2021 | A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated datab... |
| CVE-2021-20600 | MEDIUM | 5.9 | 2.2% | Oct 8, 2021 | Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versi... |
| CVE-2021-41976 | MEDIUM | 5.3 | 1.0% | Oct 8, 2021 | Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function t... |
| CVE-2021-41918 | MEDIUM | 5.4 | 0.5% | Oct 8, 2021 | webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect s... |
| CVE-2021-41917 | MEDIUM | 5.4 | 0.5% | Oct 8, 2021 | webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or edit... |
| CVE-2021-41825 | MEDIUM | 5.3 | 1.1% | Oct 8, 2021 | Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now