2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-41329 | MEDIUM | 6.5 | 1.0% | Sep 27, 2021 | Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not cons... |
| CVE-2021-40349 | MEDIUM | 5.3 | 1.1% | Sep 27, 2021 | e7d Speed Test (aka speedtest) 0.5.3 allows a path-traversal attack that results in information disclosure via the "GET ... |
| CVE-2021-31604 | MEDIUM | 6.5 | 0.7% | Sep 27, 2021 | furlongm openvpn-monitor through 1.1.3 allows CSRF to disconnect an arbitrary client. |
| CVE-2021-3830 | MEDIUM | 5.4 | 0.5% | Sep 26, 2021 | btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-21742 | MEDIUM | 5.5 | 0.6% | Sep 25, 2021 | There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter s... |
| CVE-2021-40654 | MEDIUM | 6.5 | 1.8% | Sep 24, 2021 | An information disclosure issue exist in D-LINK-DIR-615 B2 2.01mt. An attacker can obtain a user name and password by fo... |
| CVE-2021-39246 | MEDIUM | 6.1 | 0.5% | Sep 24, 2021 | Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits... |
| CVE-2021-22868 | MEDIUM | 4.3 | 0.9% | Sep 24, 2021 | A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub... |
| CVE-2021-40310 | MEDIUM | 5.4 | 0.8% | Sep 24, 2021 | OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.ph... |
| CVE-2021-40100 | MEDIUM | 5.4 | 0.5% | Sep 24, 2021 | An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversatio... |
| CVE-2021-36749 | MEDIUM | 6.5 | 81.0% | Sep 24, 2021 | In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP In... |
| CVE-2021-41583 | MEDIUM | 6.5 | 1.8% | Sep 24, 2021 | vpn-user-portal (aka eduVPN or Let's Connect!) before 2.3.14, as packaged for Debian 10, Debian 11, and Fedora, allows r... |
| CVE-2021-41581 | MEDIUM | 5.5 | 0.6% | Sep 24, 2021 | x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buff... |
| CVE-2021-31923 | MEDIUM | 5.3 | 0.7% | Sep 24, 2021 | Ping Identity PingAccess before 5.3.3 allows HTTP request smuggling via header manipulation. |
| CVE-2021-38877 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 is vulnerable to stored cross-site scripting. This vulnerability allows users t... |
| CVE-2021-38870 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Aspera Cloud is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaSc... |
| CVE-2021-29905 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site scripting. This ... |
| CVE-2021-29904 | MEDIUM | 5.5 | 0.2% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear tex... |
| CVE-2021-29833 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting... |
| CVE-2021-29832 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting... |
| CVE-2021-29816 | MEDIUM | 6.5 | 0.4% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to cross-site request forgery ... |
| CVE-2021-29815 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting... |
| CVE-2021-29814 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting... |
| CVE-2021-29813 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting... |
| CVE-2021-29812 | MEDIUM | 5.4 | 0.5% | Sep 23, 2021 | IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to stored cross-site scripting... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now