2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36787 | MEDIUM | 5.4 | 1.3% | Aug 13, 2021 | The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document. |
| CVE-2021-36785 | MEDIUM | 5.4 | 0.5% | Aug 13, 2021 | The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS. |
| CVE-2021-38554 | MEDIUM | 5.3 | 0.9% | Aug 13, 2021 | HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a singl... |
| CVE-2021-38553 | MEDIUM | 4.4 | 0.3% | Aug 13, 2021 | HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Int... |
| CVE-2021-37703 | MEDIUM | 4.3 | 0.8% | Aug 13, 2021 | Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a use... |
| CVE-2021-37586 | MEDIUM | 4.9 | 0.8% | Aug 13, 2021 | The PowerPlay Web component of Mitel Interaction Recording Multitenancy systems before 6.7 could allow a user (with Admi... |
| CVE-2021-37028 | MEDIUM | 6.7 | 0.3% | Aug 13, 2021 | There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is ... |
| CVE-2021-32072 | MEDIUM | 6.5 | 0.8% | Aug 13, 2021 | The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code informatio... |
| CVE-2021-32070 | MEDIUM | 5.4 | 0.6% | Aug 13, 2021 | The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking att... |
| CVE-2021-32069 | MEDIUM | 4.8 | 0.5% | Aug 13, 2021 | The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to impr... |
| CVE-2021-32067 | MEDIUM | 6.5 | 0.7% | Aug 13, 2021 | The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system info... |
| CVE-2021-29880 | MEDIUM | 6.5 | 0.9% | Aug 13, 2021 | IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information discl... |
| CVE-2021-27402 | MEDIUM | 6.5 | 1.1% | Aug 13, 2021 | The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify... |
| CVE-2021-27401 | MEDIUM | 6.1 | 0.6% | Aug 13, 2021 | The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) us... |
| CVE-2021-38619 | MEDIUM | 6.1 | 2.0% | Aug 13, 2021 | openBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduc... |
| CVE-2021-3635 | MEDIUM | 4.4 | 0.2% | Aug 13, 2021 | A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_AD... |
| CVE-2021-3573 | MEDIUM | 6.4 | 0.4% | Aug 13, 2021 | A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls io... |
| CVE-2021-38583 | MEDIUM | 6.1 | 1.5% | Aug 13, 2021 | openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (... |
| CVE-2021-31399 | MEDIUM | 5.9 | 0.9% | Aug 13, 2021 | On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack. |
| CVE-2021-37352 | MEDIUM | 6.1 | 6.1% | Aug 13, 2021 | An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vuln... |
| CVE-2021-37351 | MEDIUM | 5.3 | 2.8% | Aug 13, 2021 | Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded ... |
| CVE-2021-37695 | MEDIUM | 5.4 | 1.3% | Aug 13, 2021 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered ... |
| CVE-2021-37690 | MEDIUM | 6.6 | 0.2% | Aug 13, 2021 | TensorFlow is an end-to-end open source platform for machine learning. In affected versions when running shape functions... |
| CVE-2021-38603 | MEDIUM | 4.8 | 1.1% | Aug 12, 2021 | PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field. |
| CVE-2021-38602 | MEDIUM | 4.8 | 0.8% | Aug 12, 2021 | PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now