2021 CVE Vulnerabilities
23,448 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36563 | MEDIUM | 5.4 | 1.7% | Jul 26, 2021 | The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the W... |
| CVE-2021-32792 | MEDIUM | 6.1 | 1.5% | Jul 26, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-32791 | MEDIUM | 5.9 | 1.5% | Jul 26, 2021 | mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co... |
| CVE-2021-32790 | MEDIUM | 4.9 | 1.3% | Jul 26, 2021 | Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sit... |
| CVE-2021-32631 | MEDIUM | 6.5 | 1.1% | Jul 26, 2021 | Common is a package of common modules that can be accessed by NIMBLE services. Common before commit number 3b96cb0293d34... |
| CVE-2021-37534 | MEDIUM | 5.4 | 0.5% | Jul 26, 2021 | app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster. |
| CVE-2021-3664 | MEDIUM | 5.3 | 1.8% | Jul 26, 2021 | url-parse is vulnerable to URL Redirection to Untrusted Site |
| CVE-2021-35030 | MEDIUM | 4.3 | 0.3% | Jul 26, 2021 | A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize p... |
| CVE-2021-29784 | MEDIUM | 4.3 | 1.0% | Jul 26, 2021 | IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed tec... |
| CVE-2021-29770 | MEDIUM | 6.5 | 0.6% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform ... |
| CVE-2021-29769 | MEDIUM | 4.3 | 0.5% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authoriz... |
| CVE-2021-29767 | MEDIUM | 5.3 | 1.3% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information ... |
| CVE-2021-29766 | MEDIUM | 5.3 | 1.3% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi... |
| CVE-2021-22144 | MEDIUM | 6.5 | 1.7% | Jul 26, 2021 | In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial o... |
| CVE-2021-20560 | MEDIUM | 5.4 | 0.6% | Jul 26, 2021 | IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the click... |
| CVE-2021-20431 | MEDIUM | 6.5 | 0.9% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an ... |
| CVE-2021-20430 | MEDIUM | 5.3 | 1.3% | Jul 26, 2021 | IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi... |
| CVE-2021-36092 | MEDIUM | 6.1 | 0.7% | Jul 26, 2021 | It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This is... |
| CVE-2021-36091 | MEDIUM | 4.3 | 0.7% | Jul 26, 2021 | Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS))... |
| CVE-2021-21443 | MEDIUM | 4.3 | 0.9% | Jul 26, 2021 | Agents are able to list customer user emails without required permissions in the bulk action screen. This issue affects:... |
| CVE-2021-21442 | MEDIUM | 5.4 | 0.6% | Jul 26, 2021 | In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed... |
| CVE-2021-21440 | MEDIUM | 6.5 | 0.8% | Jul 26, 2021 | Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: O... |
| CVE-2021-37449 | MEDIUM | 5.4 | 0.5% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected). |
| CVE-2021-37448 | MEDIUM | 5.4 | 0.5% | Jul 25, 2021 | Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored). |
| CVE-2021-37446 | MEDIUM | 4.3 | 1.2% | Jul 25, 2021 | In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file re... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now