2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-35060MEDIUM5.3/way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response difference...
CVE-2021-35059MEDIUM6.1OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter.
CVE-2021-41831MEDIUM5.3It is possible for an attacker to manipulate the timestamp of signed documents. All versions of Apache OpenOffice up to ...
CVE-2021-41800MEDIUM5.3MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visi...
CVE-2021-41798MEDIUM6.1MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Se...
CVE-2021-42137MEDIUM5.3An issue was discovered in Zammad before 5.0.1. In some cases, there is improper enforcement of the privilege requiremen...
CVE-2021-42134MEDIUM6.1The Unicorn framework before 0.36.1 for Django allows XSS via a component. NOTE: this issue exists because of an incompl...
CVE-2021-37976MEDIUM6.5Inappropriate implementation in Memory in Google Chrome prior to 94.0.4606.71 allowed a remote attacker to obtain potent...
CVE-2021-37971MEDIUM4.3Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to spoof the co...
CVE-2021-37968MEDIUM4.3Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to...
CVE-2021-37967MEDIUM4.3Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker wh...
CVE-2021-37966MEDIUM4.3Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker ...
CVE-2021-37965MEDIUM4.3Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to...
CVE-2021-37963MEDIUM4.3Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass ...
CVE-2021-37958MEDIUM5.4Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker t...
CVE-2021-42112MEDIUM6.1The "File upload question" functionality in LimeSurvey 3.x-LTS through 3.27.18 allows XSS in assets/scripts/modaldialog....
CVE-2021-30630MEDIUM4.3Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromis...
CVE-2021-29906MEDIUM5.5IBM App Connect Enterprise Certified Container 1.0, 1.1, 1.2, 1.3, 1.4 and 1.5 could disclose sensitive information to a...
CVE-2021-41802MEDIUM5.4HashiCorp Vault and Vault Enterprise through 1.7.4 and 1.8.3 allowed a user with write permission to an entity alias ID ...
CVE-2021-32029MEDIUM6.5A flaw was found in postgresql. Using an UPDATE ... RETURNING command on a purpose-crafted table, an authenticated datab...
CVE-2021-20600MEDIUM5.9Uncontrolled resource consumption in Mitsubishi Electric MELSEC iQ-R series C Controller Module R12CCPU-V Firmware Versi...
CVE-2021-41976MEDIUM5.3Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function t...
CVE-2021-41918MEDIUM5.4webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect s...
CVE-2021-41917MEDIUM5.4webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or edit...
CVE-2021-41825MEDIUM5.3Verint Workforce Optimization (WFO) 15.2.5.1033 allows HTML injection via the /wfo/control/signin username parameter.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now