2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-37540MEDIUM6.5In JetBrains Hub before 2021.1.13262, a potentially insufficient CSP for the Widget deployment feature was used.
CVE-2021-22295MEDIUM5.5A component of the HarmonyOS has a permission bypass vulnerability. Local attackers may exploit this vulnerability to ca...
CVE-2021-38152MEDIUM5.4index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS.
CVE-2021-38151MEDIUM5.4index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS.
CVE-2021-38149MEDIUM5.4index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS.
CVE-2021-32597MEDIUM5.4Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions...
CVE-2021-32587MEDIUM4.3An improper access control vulnerability in FortiManager and FortiAnalyzer GUI interface 7.0.0, 6.4.5 and below, 6.2.8 a...
CVE-2021-3642MEDIUM5.3A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final ...
CVE-2021-3566MEDIUM5.5Prior to ffmpeg version 4.3, the tty demuxer did not have a 'read_probe' function assigned to it. By crafting a legitima...
CVE-2021-34638MEDIUM6.5Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to o...
CVE-2021-32003MEDIUM5.5Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture ...
CVE-2021-22925MEDIUM5.3curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used ...
CVE-2021-22923MEDIUM5.3When curl is instructed to get content using the metalink feature, and a user name and password are used to download the...
CVE-2021-22922MEDIUM6.5When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided ...
CVE-2021-22920MEDIUM6.5A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known a...
CVE-2021-22234MEDIUM6.4An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions sta...
CVE-2021-21792MEDIUM5.5An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handl...
CVE-2021-21791MEDIUM5.5An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handl...
CVE-2021-21790MEDIUM5.5An information disclosure vulnerability exists in the the way IOBit Advanced SystemCare Ultimate 14.2.0.220 driver handl...
CVE-2021-21785MEDIUM5.5An information disclosure vulnerability exists in the IOCTL 0x9c40a148 handling of IOBit Advanced SystemCare Ultimate 14...
CVE-2021-20116MEDIUM6.1A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.4. The paths provided in the f, d, and dir param...
CVE-2021-20115MEDIUM6.1A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir param...
CVE-2021-3679MEDIUM5.5A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the w...
CVE-2021-37859MEDIUM6.1Fixed a bypass for a reflected cross-site scripting vulnerability affecting OAuth-enabled instances of Mattermost.
CVE-2021-36584MEDIUM5.5An issue was discovered in GPAC 1.0.1. There is a heap-based buffer overflow in the function gp_rtp_builder_do_tx3g func...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now