2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-37540 | MEDIUM | 6.5 | 0.7% | Aug 6, 2021 | In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used. |
| CVE-2021-22295 | MEDIUM | 5.5 | 0.1% | Aug 6, 2021 | A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to ca... |
| CVE-2021-38152 | MEDIUM | 5.4 | 1.0% | Aug 6, 2021 | index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS. |
| CVE-2021-38151 | MEDIUM | 5.4 | 0.6% | Aug 6, 2021 | index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS. |
| CVE-2021-38149 | MEDIUM | 5.4 | 0.7% | Aug 6, 2021 | index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS. |
| CVE-2021-32597 | MEDIUM | 5.4 | 0.6% | Aug 6, 2021 | Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions... |
| CVE-2021-32587 | MEDIUM | 4.3 | 0.6% | Aug 6, 2021 | An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 a... |
| CVE-2021-3642 | MEDIUM | 5.3 | 0.8% | Aug 5, 2021 | A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final ... |
| CVE-2021-3566 | MEDIUM | 5.5 | 0.9% | Aug 5, 2021 | Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitima... |
| CVE-2021-34638 | MEDIUM | 6.5 | 1.3% | Aug 5, 2021 | Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to o... |
| CVE-2021-32003 | MEDIUM | 5.5 | 0.2% | Aug 5, 2021 | Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture ... |
| CVE-2021-22925 | MEDIUM | 5.3 | 4.9% | Aug 5, 2021 | curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used ... |
| CVE-2021-22923 | MEDIUM | 5.3 | 1.8% | Aug 5, 2021 | When curl is instructed to get content using the metalink feature, and a user name and password are used to download the... |
| CVE-2021-22922 | MEDIUM | 6.5 | 4.3% | Aug 5, 2021 | When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided ... |
| CVE-2021-22920 | MEDIUM | 6.5 | 0.9% | Aug 5, 2021 | A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known a... |
| CVE-2021-22234 | MEDIUM | 6.4 | 1.0% | Aug 5, 2021 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions sta... |
| CVE-2021-21792 | MEDIUM | 5.5 | 0.3% | Aug 5, 2021 | An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handl... |
| CVE-2021-21791 | MEDIUM | 5.5 | 0.3% | Aug 5, 2021 | An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handl... |
| CVE-2021-21790 | MEDIUM | 5.5 | 0.3% | Aug 5, 2021 | An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handl... |
| CVE-2021-21785 | MEDIUM | 5.5 | 0.3% | Aug 5, 2021 | An information disclosure vulnerability exists in the IOCTL 0x9c40a148 handling of IOBit Advanced SystemCare Ultimate 14... |
| CVE-2021-20116 | MEDIUM | 6.1 | 0.9% | Aug 5, 2021 | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir param... |
| CVE-2021-20115 | MEDIUM | 6.1 | 0.9% | Aug 5, 2021 | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir param... |
| CVE-2021-3679 | MEDIUM | 5.5 | 0.7% | Aug 5, 2021 | A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the w... |
| CVE-2021-37859 | MEDIUM | 6.1 | 3.3% | Aug 5, 2021 | Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost. |
| CVE-2021-36584 | MEDIUM | 5.5 | 0.8% | Aug 5, 2021 | An issue was discovered in GPAC 1.0.1. There is a heap-based buffer overflow in the function gp_rtp_builder_do_tx3g func... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now