2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-38114MEDIUM5.5libavcodec/dnxhddec.c in FFmpeg 4.4 does not check the return value of the init_vlc function, a similar issue to CVE-201...
CVE-2021-38113MEDIUM5.4In addBouquet in js/bqe.js in OpenWebif (aka e2openplugin-OpenWebif) through 1.4.7, inserting JavaScript into the Add Bo...
CVE-2021-24014MEDIUM6.1Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before...
CVE-2021-34707MEDIUM6.5A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remot...
CVE-2021-32793MEDIUM4.8Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prio...
CVE-2021-1522MEDIUM4.3A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, rem...
CVE-2021-36168MEDIUM6.5A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0....
CVE-2021-24010MEDIUM6.5Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1...
CVE-2021-3678MEDIUM5.9showdoc is vulnerable to Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
CVE-2021-35463MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 allows remote attackers t...
CVE-2021-33337MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Document Library module's add document menu in Liferay Portal 7.3.0 thro...
CVE-2021-3680MEDIUM4.9showdoc is vulnerable to Missing Cryptographic Step
CVE-2021-33339MEDIUM4.8Cross-site scripting (XSS) vulnerability in the Fragment module in Liferay Portal 7.2.1 through 7.3.4, and Liferay DXP 7...
CVE-2021-33336MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Journal module's add article menu in Liferay Portal 7.3.0 through 7.3.3,...
CVE-2021-37231MEDIUM5.5A stack-buffer-overflow occurs in Atomicparsley 20210124.204813.840499f through APar_readX() in src/util.cpp while parsi...
CVE-2021-33334MEDIUM4.3The Dynamic Data Mapping module in Liferay Portal 7.0.0 through 7.3.2, and Liferay DXP 7.0 before fix pack 94, 7.1 befor...
CVE-2021-33333MEDIUM6.3The Portal Workflow module in Liferay Portal 7.3.2 and earlier, and Liferay DXP 7.0 before fix pack 93, 7.1 before fix p...
CVE-2021-33332MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Portlet Configuration module in Liferay Portal 7.1.0 through 7.3.2, and ...
CVE-2021-33331MEDIUM6.1Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 befor...
CVE-2021-30589MEDIUM4.3Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker ...
CVE-2021-30587MEDIUM4.3Inappropriate implementation in Compositing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potenti...
CVE-2021-30584MEDIUM6.5Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remote attacker to perfo...
CVE-2021-30583MEDIUM6.5Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.107 allowed a remote...
CVE-2021-30582MEDIUM6.5Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cros...
CVE-2021-30580MEDIUM6.5Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now