2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-20828MEDIUM6.1Cross-site scripting vulnerability in Order Status Batch Change Plug-in (for EC-CUBE 3.0 series) all versions allows a r...
CVE-2021-20825MEDIUM6.1Cross-site scripting vulnerability in List (order management) item change plug-in (for EC-CUBE 3.0 series) Ver.1.1 and e...
CVE-2021-29842MEDIUM5.3IBM WebSphere Application Server 7.0, 8.0, 8.5, 9.0 and Liberty 17.0.0.3 through 21.0.0.9 could allow a remote user to e...
CVE-2021-29763MEDIUM5.1IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 under very specific conditions, could al...
CVE-2021-29752MEDIUM4.4IBM Db2 11.2 and 11.5 contains an information disclosure vulnerability, exposing remote storage credentials to privilege...
CVE-2021-39208MEDIUM4.3SharpCompress is a fully managed C# library to deal with many compression types and formats. Versions prior to 0.29.0 ar...
CVE-2021-27340MEDIUM6.1OpenSIS Community Edition version <= 7.6 is affected by a reflected XSS vulnerability in EmailCheck.php via the "opt" pa...
CVE-2021-34576MEDIUM4.3In Kaden PICOFLUX Air in all known versions an information exposure through observable discrepancy exists. This may give...
CVE-2021-34573MEDIUM5.5In Enbra EWM in Version 1.7.29 together with several tested wireless M-Bus Sensors the events backflow and "no flow" are...
CVE-2021-34572MEDIUM6.5Enbra EWM 1.7.29 does not check for or detect replay attacks sent by wireless M-Bus Security mode 5 devices. Instead tim...
CVE-2021-34571MEDIUM6.5Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an option to change the e...
CVE-2021-40067MEDIUM6.8The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by ...
CVE-2021-40066MEDIUM5.3The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both netwo...
CVE-2021-33697MEDIUM6.1Under certain conditions, SAP BusinessObjects Business Intelligence Platform (SAPUI5), versions - 420, 430, can allow an...
CVE-2021-33696MEDIUM5.4SAP BusinessObjects Business Intelligence Platform (Crystal Report), versions - 420, 430, does not sufficiently encode u...
CVE-2021-33694MEDIUM4.8SAP Cloud Connector, version - 2.0, does not sufficiently encode user-controlled inputs, allowing an attacker with Admin...
CVE-2021-33693MEDIUM6.8SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malic...
CVE-2021-33691MEDIUM6.1NWDI Notification Service versions - 7.31, 7.40, 7.50, does not sufficiently encode user-controlled inputs, resulting in...
CVE-2021-40966MEDIUM5.4A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is ...
CVE-2021-40964MEDIUM6.5A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to ...
CVE-2021-39205MEDIUM6.1Jitsi Meet is an open source video conferencing application. Versions prior to 2.0.6173 are vulnerable to client-side cr...
CVE-2021-29773MEDIUM5.4IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modif...
CVE-2021-28901MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities exist in SITA Software Azur CMS 1.2.3.1 and earlier, which allows re...
CVE-2021-20433MEDIUM6.5IBM Security Guardium 11.3 could allow a an authenticated user to obtain sensitive information that could be used in fur...
CVE-2021-40238MEDIUM6.1A Cross Site Scriptiong (XSS) vulnerability exists in the admin panel in Webuzo < 2.9.0 via an HTTP request to a non-exi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now