2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-3692MEDIUM5.3yii2 is vulnerable to Use of Predictable Algorithm in Random Number Generator
CVE-2021-37365MEDIUM6.1CTparental before 4.45.03 is vulnerable to cross-site scripting (XSS) in the CTparental admin panel. In bl_categires_hel...
CVE-2021-32768MEDIUM6.1TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions failing...
CVE-2021-38373MEDIUM5.3In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Ser...
CVE-2021-38370MEDIUM5.9In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.
CVE-2021-36601MEDIUM6.1GetSimpleCMS 3.3.16 contains a cross-site Scripting (XSS) vulnerability, where Function TSL does not filter check settin...
CVE-2021-33707MEDIUM6.1SAP NetWeaver Knowledge Management allows remote attackers to redirect users to arbitrary websites and conduct phishing ...
CVE-2021-33706MEDIUM4.3Due to improper input validation in InfraBox, logs can be modified by an authenticated user.
CVE-2021-33703MEDIUM6.1Under certain conditions, NetWeaver Enterprise Portal, versions - 7.30, 7.31, 7.40, 7.50, does not sufficiently encode U...
CVE-2021-33702MEDIUM6.1Under certain conditions, NetWeaver Enterprise Portal, versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not suf...
CVE-2021-33699MEDIUM6.5Task Hijacking is a vulnerability that affects the applications running on Android devices due to a misconfiguration in ...
CVE-2021-22676MEDIUM6.1UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to se...
CVE-2021-37152MEDIUM5.4Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the abili...
CVE-2021-29739MEDIUM4.9IBM Planning Analytics Local 2.0 could allow a remote attacker to obtain sensitive information when a stack trace is ret...
CVE-2021-22674MEDIUM6.5The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unautho...
CVE-2021-31655MEDIUM6.1Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP110WN V1.2.2.64 V1.2.2.65 V1.2.2.68 via the profile parameter....
CVE-2021-37178MEDIUM5.5A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vu...
CVE-2021-33717MEDIUM5.5A vulnerability has been identified in JT2Go (All versions < V13.2.0.1), Teamcenter Visualization (All versions < V13.2....
CVE-2021-21584MEDIUM6.5Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosu...
CVE-2021-37634MEDIUM6.1Leafkit is a templating language with Swift-inspired syntax. Versions prior to 1.3.0 are susceptible to Cross-site Scrip...
CVE-2021-37633MEDIUM6.1Discourse is an open source discussion platform. In versions prior to 2.7.8 rendering of d-popover tooltips can be susce...
CVE-2021-37615MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-34335MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-37622MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-37621MEDIUM5.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now