2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41329MEDIUM6.5Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not cons...
CVE-2021-40349MEDIUM5.3e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET ...
CVE-2021-31604MEDIUM6.5furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client.
CVE-2021-3830MEDIUM5.4btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21742MEDIUM5.5There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter s...
CVE-2021-40654MEDIUM6.5An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by fo...
CVE-2021-39246MEDIUM6.1Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits...
CVE-2021-22868MEDIUM4.3A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub...
CVE-2021-40310MEDIUM5.4OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.ph...
CVE-2021-40100MEDIUM5.4An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversatio...
CVE-2021-36749MEDIUM6.5In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP In...
CVE-2021-41583MEDIUM6.5vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows r...
CVE-2021-41581MEDIUM5.5x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buff...
CVE-2021-31923MEDIUM5.3Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation.
CVE-2021-38877MEDIUM5.4IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users t...
CVE-2021-38870MEDIUM5.4IBM Aspera Cloud is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc...
CVE-2021-29905MEDIUM5.4IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site scripting. This ...
CVE-2021-29904MEDIUM5.5IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear tex...
CVE-2021-29833MEDIUM5.4IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting...
CVE-2021-29832MEDIUM5.4IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting...
CVE-2021-29816MEDIUM6.5IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery ...
CVE-2021-29815MEDIUM5.4IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting...
CVE-2021-29814MEDIUM5.4IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting...
CVE-2021-29813MEDIUM5.4IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting...
CVE-2021-29812MEDIUM5.4IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now