2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24428MEDIUM4.8The RSS for Yandex Turbo WordPress plugin through 1.30 does not sanitise or escape some of its settings before saving an...
CVE-2021-24425MEDIUM4.8The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin be...
CVE-2021-3351MEDIUM5.4OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page.
CVE-2021-34556MEDIUM5.5In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via ...
CVE-2021-35477MEDIUM5.5In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via ...
CVE-2021-33617MEDIUM5.3Zoho ManageEngine Password Manager Pro before 11.2 11200 allows login/AjaxResponse.jsp?RequestType=GetUserDomainName&use...
CVE-2021-34630MEDIUM6.1In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of al...
CVE-2021-34629MEDIUM4.3The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/...
CVE-2021-22521MEDIUM6.7A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting ve...
CVE-2021-3636MEDIUM4.6It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly...
CVE-2021-29298MEDIUM5.3Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of ...
CVE-2021-29297MEDIUM5.3Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service an...
CVE-2021-37746MEDIUM6.1textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have suffici...
CVE-2021-37743MEDIUM5.4app/View/GalaxyElements/ajax/index.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster elements in JSON fo...
CVE-2021-37742MEDIUM5.4app/View/Elements/GalaxyClusters/view_relation_tree.ctp in MISP 2.4.147 allows Stored XSS when viewing galaxy cluster re...
CVE-2021-37606MEDIUM5.3Meow hash 0.5/calico does not sufficiently thwart key recovery by an attacker who can query whether there's a collision ...
CVE-2021-37600MEDIUM5.5An integer overflow in util-linux through 2.37.1 can potentially cause a buffer overflow if an attacker were able to use...
CVE-2021-37596MEDIUM6.1Telegram Web K Alpha 0.6.1 allows XSS via a document name.
CVE-2021-37588MEDIUM5.9In Charm 0.43, any two users can collude to achieve the ability to decrypt YCT14 data.
CVE-2021-37587MEDIUM6.5In Charm 0.43, any single user can decrypt DAC-MACS or MA-ABE-YJ14 data.
CVE-2021-36605MEDIUM5.4engineercms 1.03 is vulnerable to Cross Site Scripting (XSS). There is no escaping in the nickname field on the user lis...
CVE-2021-35479MEDIUM5.4Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log functio...
CVE-2021-35478MEDIUM5.4Nagios Log Server before 2.1.9 contains Reflected XSS in the dropdown box for the alert history and audit log function. ...
CVE-2021-31878MEDIUM6.5An issue was discovered in PJSIP in Asterisk before 16.19.1 and before 18.5.1. To exploit, a re-INVITE without SDP must ...
CVE-2021-30483MEDIUM5.3isomorphic-git before 1.8.2 allows Directory Traversal via a crafted repository.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now