2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-20757MEDIUM4.3Operational restrictions bypass vulnerability in E-mail of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated at...
CVE-2021-20756MEDIUM4.3Viewing restrictions bypass vulnerability in Address of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attac...
CVE-2021-20755MEDIUM4.3Viewing restrictions bypass vulnerability in Portal of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attack...
CVE-2021-20754MEDIUM4.3Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attack...
CVE-2021-20753MEDIUM5.4Cross-site scripting vulnerability in Scheduler of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker t...
CVE-2021-39268MEDIUM6.1Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introd...
CVE-2021-39267MEDIUM6.1Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introd...
CVE-2021-39250MEDIUM5.4Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution...
CVE-2021-39249MEDIUM6.1Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of up...
CVE-2021-39248MEDIUM6.1Open edX through Lilac.1 allows XSS in common/static/common/js/discussion/utils.js via crafted LaTeX content within a di...
CVE-2021-39247MEDIUM6.5Zint Barcode Generator before 2.10.0 has a one-byte buffer over-read, related to is_last_single_ascii in code1.c, and rs...
CVE-2021-38702MEDIUM6.1Cyberoam NetGenie C0101B1-20141120-NG11VO devices through 2021-08-14 allow tweb/ft.php?u=[XSS] attacks.
CVE-2021-29987MEDIUM6.5After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be disp...
CVE-2021-29983MEDIUM6.5Firefox for Android could get stuck in fullscreen mode and not exit it even after normal interactions that should cause ...
CVE-2021-29982MEDIUM6.5Due to incorrect JIT optimization, we incorrectly interpreted data from the wrong type of object, resulting in the poten...
CVE-2021-39241MEDIUM5.3An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTT...
CVE-2021-29313MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in SeaCMS 12.6 via the (1) v_company and (2) v_tvs parameters in /admin_...
CVE-2021-0642MEDIUM5.5In onResume of VoicemailSettingsFragment.java, there is a possible way to retrieve a trackable identifier without permis...
CVE-2021-0641MEDIUM5.5In getAvailableSubscriptionInfoList of SubscriptionController.java, there is a possible disclosure of unique identifiers...
CVE-2021-0639MEDIUM5.5In multiple functions of libl3oemcrypto.cpp, there is a possible weakness in the existing obfuscation mechanism due to t...
CVE-2021-0584MEDIUM5.5In verifyBufferObject of Parcel.cpp, there is a possible out of bounds read due to an improper input validation. This co...
CVE-2021-0582MEDIUM6.5In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informat...
CVE-2021-0581MEDIUM6.5In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informat...
CVE-2021-0580MEDIUM6.5In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informat...
CVE-2021-0579MEDIUM6.5In wifi driver, there is a possible out of bounds read due to a missing bounds check. This could lead to remote informat...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now