2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36787MEDIUM5.4The femanager extension before 5.5.1 and 6.x before 6.3.1 for TYPO3 allows XSS via a crafted SVG document.
CVE-2021-36785MEDIUM5.4The miniorange_saml (aka Miniorange Saml) extension before 1.4.3 for TYPO3 allows XSS.
CVE-2021-38554MEDIUM5.3HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a singl...
CVE-2021-38553MEDIUM4.4HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Int...
CVE-2021-37703MEDIUM4.3Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta5, a use...
CVE-2021-37586MEDIUM4.9The PowerPlay Web component of Mitel Interaction Recording Multitenancy systems before 6.7 could allow a user (with Admi...
CVE-2021-37028MEDIUM6.7There is a command injection vulnerability in the HG8045Q product. When the command-line interface is enabled, which is ...
CVE-2021-32072MEDIUM6.5The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to get source code informatio...
CVE-2021-32070MEDIUM5.4The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to perform a clickjacking att...
CVE-2021-32069MEDIUM4.8The AWV component of Mitel MiCollab before 9.3 could allow an attacker to perform a Man-In-the-Middle attack due to impr...
CVE-2021-32067MEDIUM6.5The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to view sensitive system info...
CVE-2021-29880MEDIUM6.5IBM QRadar SIEM 7.4.3 GA - 7.4.3 Fix Pack 1 when using domains or multi-tenancy could be vulnerable to information discl...
CVE-2021-27402MEDIUM6.5The SAS Admin portal of Mitel MiCollab before 9.2 FP2 could allow an unauthenticated attacker to access (view and modify...
CVE-2021-27401MEDIUM6.1The Join Meeting page of Mitel MiCollab Web Client before 9.2 FP2 could allow an attacker to access (view and modify) us...
CVE-2021-38619MEDIUM6.1openBaraza HCM 3.1.6 does not properly neutralize user-controllable input: an unauthenticated remote attacker can conduc...
CVE-2021-3635MEDIUM4.4A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_AD...
CVE-2021-3573MEDIUM6.4A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls io...
CVE-2021-38583MEDIUM6.1openBaraza HCM 3.1.6 does not properly neutralize user-controllable input, which allows reflected cross-site scripting (...
CVE-2021-31399MEDIUM5.9On 2N Access Unit 2.0 2.31.0.40.5 devices, an attacker can pose as the web relay for a man-in-the-middle attack.
CVE-2021-37352MEDIUM6.1An open redirect vulnerability exists in Nagios XI before version 5.8.5 that could lead to spoofing. To exploit the vuln...
CVE-2021-37351MEDIUM5.3Nagios XI before version 5.8.5 is vulnerable to insecure permissions and allows unauthenticated users to access guarded ...
CVE-2021-37695MEDIUM5.4ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered ...
CVE-2021-37690MEDIUM6.6TensorFlow is an end-to-end open source platform for machine learning. In affected versions when running shape functions...
CVE-2021-38603MEDIUM4.8PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
CVE-2021-38602MEDIUM4.8PluXML 5.8.7 allows Article Editing stored XSS via Headline or Content.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now