2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-37151MEDIUM5.3CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is v...
CVE-2021-35238MEDIUM4.8User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website.
CVE-2021-40085MEDIUM6.5An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated at...
CVE-2021-37794MEDIUM5.4A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user auth...
CVE-2021-36234MEDIUM5.5Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspeci...
CVE-2021-36233MEDIUM6.5The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacke...
CVE-2021-27668MEDIUM5.3HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authenti...
CVE-2021-3634MEDIUM6.5A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during th...
CVE-2021-22929MEDIUM6.1An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that i...
CVE-2021-35240MEDIUM4.8A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they...
CVE-2021-35239MEDIUM5.4A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink.
CVE-2021-21681MEDIUM5.5Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins ...
CVE-2021-35219MEDIUM4.9ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability using ImportAlert function within the Alerts Set...
CVE-2021-34564MEDIUM5.5Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's crede...
CVE-2021-34562MEDIUM6.1In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's respons...
CVE-2021-34560MEDIUM5.5In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored cr...
CVE-2021-34559MEDIUM5.3In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in c...
CVE-2021-38144MEDIUM5.4An issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a f...
CVE-2021-38143MEDIUM6.1An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible f...
CVE-2021-27558MEDIUM6.1A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via...
CVE-2021-27557MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to upda...
CVE-2021-39178MEDIUM6.1Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability...
CVE-2021-39175MEDIUM6.1HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject a...
CVE-2021-36692MEDIUM6.5libjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding...
CVE-2021-32832MEDIUM6.5Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now