2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36156MEDIUM5.3An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths fo...
CVE-2021-22400MEDIUM5.5Some Huawei Smartphones has an insufficient input validation vulnerability due to the lack of parameter validation. An a...
CVE-2021-37833MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability exists in multiple pages in version 3.0.2 of the Hotel Druid applic...
CVE-2021-35265MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in MaxSite CMS before V106 via product/page/* allows remote attacke...
CVE-2021-37916MEDIUM6.1Joplin before 2.0.9 allows XSS via button and form in the note body.
CVE-2021-37914MEDIUM6.5In Argo Workflows through 3.1.3, if EXPRESSION_TEMPLATES is enabled and untrusted users are allowed to specify input par...
CVE-2021-26085MEDIUM5.3Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza...
CVE-2021-21565MEDIUM5.3Dell PowerScale OneFS versions 9.1.0.3 and earlier contain a denial of service vulnerability. SmartConnect had an error ...
CVE-2021-21563MEDIUM6.5Dell EMC PowerScale OneFS versions 8.1.2-9.1.0.x contain an Improper Check for Unusual or Exceptional Conditions in its ...
CVE-2021-21562MEDIUM4.4Dell EMC PowerScale OneFS contains an untrusted search path vulnerability. This vulnerability allows a user with (ISI_PR...
CVE-2021-32812MEDIUM6.1Monkshu is an enterprise application server for mobile apps (iOS and Android), responsive HTML 5 apps, and JSON API serv...
CVE-2021-32787MEDIUM4.3Sourcegraph is a code search and navigation engine. Sourcegraph before version 3.30.0 has two potential information leak...
CVE-2021-34635MEDIUM6.1The Poll Maker WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the mcount parameter found in the ~/...
CVE-2021-32019MEDIUM6.1There is missing input validation of host names displayed in OpenWrt before 19.07.8. The Connection Status page of the l...
CVE-2021-29979MEDIUM6.1Hubs Cloud allows users to download shared content, specifically HTML and JS, which could allow javascript execution in ...
CVE-2021-27503MEDIUM4.8Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: ...
CVE-2021-27499MEDIUM5.9Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7.2, Ypsomed mylife App: ...
CVE-2021-33197MEDIUM5.3In Go before 1.15.13 and 1.16.x before 1.16.5, some configurations of ReverseProxy (from net/http/httputil) result in a ...
CVE-2021-32806MEDIUM6.1Products.isurlinportal is a replacement for isURLInPortal method in Plone. Versions of Products.isurlinportal prior to 1...
CVE-2021-29697MEDIUM4.9IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could allow a remote authenti...
CVE-2021-22398MEDIUM4.6There is a logic error vulnerability in several smartphones. The software does not properly restrict certain operation w...
CVE-2021-22397MEDIUM6.7There is a privilege escalation vulnerability in Huawei ManageOne 8.0.0. External parameters of some files are lack of v...
CVE-2021-20541MEDIUM5.3IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive info...
CVE-2021-20540MEDIUM5.3IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive info...
CVE-2021-20539MEDIUM5.3IBM Cloud Pak for Security (CP4S) 1.5.0.0, 1.5.1.0, 1.6.0.0, 1.6.1.0, 1.7.0.0, and 1.7.1.0 could disclose sensitive info...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now