2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-39117MEDIUM4.8The AssociateFieldToScreens page in Atlassian Jira Server and Data Center before version 8.18.0 allows remote attackers ...
CVE-2021-39111MEDIUM6.1The Editor plugin in Atlassian Jira Server and Data Center before version 8.5.18, from 8.6.0 before 8.13.10, and from ve...
CVE-2021-39272MEDIUM5.9Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation ...
CVE-2021-40178MEDIUM6.1Zoho ManageEngine Log360 before Build 5224 allows stored XSS via the LOGO_PATH key value in the logon settings.
CVE-2021-40176MEDIUM6.1Zoho ManageEngine Log360 before Build 5225 allows stored XSS.
CVE-2021-28700MEDIUM4.9xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged...
CVE-2021-28699MEDIUM5.5inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant ...
CVE-2021-28698MEDIUM5.5long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the g...
CVE-2021-28696MEDIUM6.8IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/...
CVE-2021-28695MEDIUM6.8IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/...
CVE-2021-28694MEDIUM6.8IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/...
CVE-2021-29744MEDIUM5.4IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to cross-site scripting. This vulnerability allows users to em...
CVE-2021-39169MEDIUM5.4Misskey is a decentralized microblogging platform. In versions of Misskey prior to 12.51.0, malicious actors can use the...
CVE-2021-39165MEDIUM6.5Cachet is an open source status page. With Cachet prior to and including 2.3.18, there is a SQL injection which is in th...
CVE-2021-39161MEDIUM5.4Discourse is an open source platform for community discussion. In affected versions category names can be used for Cross...
CVE-2021-37715MEDIUM4.8A remote cross-site scripting (XSS) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior ...
CVE-2021-29862MEDIUM5.5IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to c...
CVE-2021-29727MEDIUM5.5IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user to exploit a vulnerability in the AIX kernel to cause a denial o...
CVE-2021-36931MEDIUM4.4Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2021-36929MEDIUM6.3Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2021-36928MEDIUM6Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2021-30597MEDIUM6.8Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially ...
CVE-2021-30596MEDIUM4.3Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a remote attacker to spoo...
CVE-2021-30594MEDIUM6.8Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit ...
CVE-2021-32076MEDIUM5.3Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now