2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41568MEDIUM6.5Tad Web is vulnerable to authorization bypass, thus remote attackers can exploit the vulnerability to use the original f...
CVE-2021-41567MEDIUM6.1The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticate...
CVE-2021-41565MEDIUM6.1TadTools special page parameter does not properly restrict the input of specific characters, thus remote attackers can i...
CVE-2021-41564MEDIUM6.5Tad Honor viewing book list function is vulnerable to authorization bypass, thus remote attackers can use special parame...
CVE-2021-41563MEDIUM6.1Tad Book3 editing book function does not filter special characters. Unauthenticated attackers can remotely inject JavaSc...
CVE-2021-3312MEDIUM6.5An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users ...
CVE-2021-40832MEDIUM6.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component u...
CVE-2021-33603MEDIUM6.5A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in ce...
CVE-2021-25271MEDIUM6A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318...
CVE-2021-25270MEDIUM6.7A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.
CVE-2021-41115MEDIUM6.5Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to c...
CVE-2021-42088MEDIUM6.1An issue was discovered in Zammad before 4.1.1. The Chat functionality allows XSS because clipboard data is mishandled.
CVE-2021-42087MEDIUM4.9An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
CVE-2021-42085MEDIUM5.4An issue was discovered in Zammad before 4.1.1. There is stored XSS via a custom Avatar.
CVE-2021-42084MEDIUM6.5An issue was discovered in Zammad before 4.1.1. An attacker with valid agent credentials may send a series of crafted re...
CVE-2021-42092MEDIUM5.4An issue was discovered in Zammad before 4.1.1. Stored XSS may occur via an Article during addition of an attachment to ...
CVE-2021-41130MEDIUM5.4Extensible Service Proxy, a.k.a. ESP is a proxy which enables API management capabilities for JSON/REST or gRPC API serv...
CVE-2021-29700MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.1.1.0 could allow an authneticated attacker to obtain sen...
CVE-2021-20571MEDIUM5.4IBM Sterling B2B Integrator 5.2.0.0 through 6.1.1.0 is vulnerable to stored cross-site scripting. This vulnerability all...
CVE-2021-20561MEDIUM6.1IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-20552MEDIUM4.3IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a d...
CVE-2021-20481MEDIUM6.1IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 is vulnerable to cross-site scripting. This vulnerability allows users...
CVE-2021-20473MEDIUM6.5IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could al...
CVE-2021-20376MEDIUM4.3IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated attacker to enumerate usernames due to th...
CVE-2021-20375MEDIUM6.5IBM Sterling File Gateway 2.2.0.0 through 6.1.1.0 could allow an authenticated user to intercept and replace a message s...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now