2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41568 | MEDIUM | 6.5 | 1.0% | Oct 8, 2021 | Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original f... |
| CVE-2021-41567 | MEDIUM | 6.1 | 0.6% | Oct 8, 2021 | The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticate... |
| CVE-2021-41565 | MEDIUM | 6.1 | 0.7% | Oct 8, 2021 | TadTools special page parameter does not properly restrict the input of specific characters, thus remote attackers can i... |
| CVE-2021-41564 | MEDIUM | 6.5 | 1.0% | Oct 8, 2021 | Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parame... |
| CVE-2021-41563 | MEDIUM | 6.1 | 0.6% | Oct 8, 2021 | Tad Book3 editing book function does not filter special characters. Unauthenticated attackers can remotely inject JavaSc... |
| CVE-2021-3312 | MEDIUM | 6.5 | 1.2% | Oct 8, 2021 | An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users ... |
| CVE-2021-40832 | MEDIUM | 6.5 | 0.5% | Oct 8, 2021 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component u... |
| CVE-2021-33603 | MEDIUM | 6.5 | 0.5% | Oct 8, 2021 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in ce... |
| CVE-2021-25271 | MEDIUM | 6 | 0.2% | Oct 8, 2021 | A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318... |
| CVE-2021-25270 | MEDIUM | 6.7 | 0.3% | Oct 8, 2021 | A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901. |
| CVE-2021-41115 | MEDIUM | 6.5 | 1.7% | Oct 7, 2021 | Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to c... |
| CVE-2021-42088 | MEDIUM | 6.1 | 0.6% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled. |
| CVE-2021-42087 | MEDIUM | 4.9 | 0.9% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API. |
| CVE-2021-42085 | MEDIUM | 5.4 | 0.5% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar. |
| CVE-2021-42084 | MEDIUM | 6.5 | 0.9% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted re... |
| CVE-2021-42092 | MEDIUM | 5.4 | 0.5% | Oct 7, 2021 | An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to ... |
| CVE-2021-41130 | MEDIUM | 5.4 | 0.4% | Oct 7, 2021 | Extensible Service Proxy, a.k.a. ESP is a proxy which enables API management capabilities for JSON/REST or gRPC API serv... |
| CVE-2021-29700 | MEDIUM | 4.3 | 0.9% | Oct 7, 2021 | IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sen... |
| CVE-2021-20571 | MEDIUM | 5.4 | 0.4% | Oct 7, 2021 | IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability all... |
| CVE-2021-20561 | MEDIUM | 6.1 | 0.6% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-20552 | MEDIUM | 4.3 | 1.0% | Oct 7, 2021 | IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a d... |
| CVE-2021-20481 | MEDIUM | 6.1 | 0.6% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users... |
| CVE-2021-20473 | MEDIUM | 6.5 | 0.5% | Oct 7, 2021 | IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could al... |
| CVE-2021-20376 | MEDIUM | 4.3 | 0.7% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to th... |
| CVE-2021-20375 | MEDIUM | 6.5 | 0.8% | Oct 7, 2021 | IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message s... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now