2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37151 | MEDIUM | 5.3 | 0.9% | Sep 1, 2021 | CyberArk Identity 21.5.131, when handling an invalid authentication attempt, sometimes reveals whether the username is v... |
| CVE-2021-35238 | MEDIUM | 4.8 | 1.1% | Sep 1, 2021 | User with Orion Platform Admin Rights could store XSS through URL POST parameter in CreateExternalWebsite website. |
| CVE-2021-40085 | MEDIUM | 6.5 | 1.9% | Aug 31, 2021 | An issue was discovered in OpenStack Neutron before 16.4.1, 17.x before 17.2.1, and 18.x before 18.1.1. Authenticated at... |
| CVE-2021-37794 | MEDIUM | 5.4 | 0.8% | Aug 31, 2021 | A stored cross-site scripting (XSS) vulnerability exists in FileBrowser < v2.16.0 that allows an authenticated user auth... |
| CVE-2021-36234 | MEDIUM | 5.5 | 0.3% | Aug 31, 2021 | Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt credentials via unspeci... |
| CVE-2021-36233 | MEDIUM | 6.5 | 1.0% | Aug 31, 2021 | The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design) an authenticated attacke... |
| CVE-2021-27668 | MEDIUM | 5.3 | 1.0% | Aug 31, 2021 | HashiCorp Vault Enterprise 0.9.2 through 1.6.2 allowed the read of license metadata from DR secondaries without authenti... |
| CVE-2021-3634 | MEDIUM | 6.5 | 4.7% | Aug 31, 2021 | A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during th... |
| CVE-2021-22929 | MEDIUM | 6.1 | 0.4% | Aug 31, 2021 | An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that i... |
| CVE-2021-35240 | MEDIUM | 4.8 | 1.1% | Aug 31, 2021 | A security researcher stored XSS via a Help Server setting. This affects customers using Internet Explorer, because they... |
| CVE-2021-35239 | MEDIUM | 5.4 | 1.0% | Aug 31, 2021 | A security researcher found a user with Orion map manage rights could store XSS through via text box hyperlink. |
| CVE-2021-21681 | MEDIUM | 5.5 | 0.3% | Aug 31, 2021 | Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins ... |
| CVE-2021-35219 | MEDIUM | 4.9 | 0.8% | Aug 31, 2021 | ExportToPdfCmd Arbitrary File Read Information Disclosure Vulnerability using ImportAlert function within the Alerts Set... |
| CVE-2021-34564 | MEDIUM | 5.5 | 0.2% | Aug 31, 2021 | Any cookie-stealing vulnerabilities within the application or browser would enable an attacker to steal the user's crede... |
| CVE-2021-34562 | MEDIUM | 6.1 | 0.6% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway 3.0.8 it is possible to inject arbitrary JavaScript into the application's respons... |
| CVE-2021-34560 | MEDIUM | 5.5 | 0.2% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.9 a form contains a password field with autocomplete enabled. The stored cr... |
| CVE-2021-34559 | MEDIUM | 5.3 | 0.8% | Aug 31, 2021 | In PEPPERL+FUCHS WirelessHART-Gateway <= 3.0.8 a vulnerability may allow remote attackers to rewrite links and URLs in c... |
| CVE-2021-38144 | MEDIUM | 5.4 | 0.9% | Aug 31, 2021 | An issue was discovered in Form Tools through 3.0.20. A low-privileged user can trigger Reflected XSS when a viewing a f... |
| CVE-2021-38143 | MEDIUM | 6.1 | 1.4% | Aug 31, 2021 | An issue was discovered in Form Tools through 3.0.20. When an administrator creates a customer account, it is possible f... |
| CVE-2021-27558 | MEDIUM | 6.1 | 0.8% | Aug 31, 2021 | A cross site scripting (XSS) issue in EasyCorp ZenTao 12.5.3 allows remote attackers to execute arbitrary web script via... |
| CVE-2021-27557 | MEDIUM | 4.3 | 0.4% | Aug 31, 2021 | A cross-site request forgery (CSRF) vulnerability in the Cron job tab in EasyCorp ZenTao 12.5.3 allows attackers to upda... |
| CVE-2021-39178 | MEDIUM | 6.1 | 1.1% | Aug 31, 2021 | Next.js is a React framework. Versions of Next.js between 10.0.0 and 11.0.0 contain a cross-site scripting vulnerability... |
| CVE-2021-39175 | MEDIUM | 6.1 | 0.6% | Aug 30, 2021 | HedgeDoc is a platform to write and share markdown. In versions prior to 1.9.0, an unauthenticated attacker can inject a... |
| CVE-2021-36692 | MEDIUM | 6.5 | 1.2% | Aug 30, 2021 | libjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding... |
| CVE-2021-32832 | MEDIUM | 6.5 | 1.6% | Aug 30, 2021 | Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now