2021 CVE Vulnerabilities

23,448 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36563MEDIUM5.4The CheckMK management web console (versions 1.5.0 to 2.0.0) does not sanitise user input in various parameters of the W...
CVE-2021-32792MEDIUM6.1mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co...
CVE-2021-32791MEDIUM5.9mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Co...
CVE-2021-32790MEDIUM4.9Woocommerce is an open source eCommerce plugin for WordPress. An SQL injection vulnerability impacts all WooCommerce sit...
CVE-2021-32631MEDIUM6.5Common is a package of common modules that can be accessed by NIMBLE services. Common before commit number 3b96cb0293d34...
CVE-2021-37534MEDIUM5.4app/View/GalaxyClusters/add.ctp in MISP 2.4.146 allows Stored XSS when forking a galaxy cluster.
CVE-2021-3664MEDIUM5.3url-parse is vulnerable to URL Redirection to Untrusted Site
CVE-2021-35030MEDIUM4.3A vulnerability was found in the CGI program in Zyxel GS1900-8 firmware version V2.60, that did not properly sterilize p...
CVE-2021-29784MEDIUM4.3IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed tec...
CVE-2021-29770MEDIUM6.5IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow an authenticated user to perform ...
CVE-2021-29769MEDIUM4.3IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) does not set the secure attribute on authoriz...
CVE-2021-29767MEDIUM5.3IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 could allow a remote attacker to obtain sensitive information ...
CVE-2021-29766MEDIUM5.3IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi...
CVE-2021-22144MEDIUM6.5In Elasticsearch versions before 7.13.3 and 6.8.17 an uncontrolled recursion vulnerability that could lead to a denial o...
CVE-2021-20560MEDIUM5.4IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote attacker to hijack the click...
CVE-2021-20431MEDIUM6.5IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an ...
CVE-2021-20430MEDIUM5.3IBM i2 Analyst's Notebook Premium (IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2) could allow a remote attacker to obtain sensi...
CVE-2021-36092MEDIUM6.1It's possible to create an email which contains specially crafted link and it can be used to perform XSS attack. This is...
CVE-2021-36091MEDIUM4.3Agents are able to list appointments in the calendars without required permissions. This issue affects: OTRS AG ((OTRS))...
CVE-2021-21443MEDIUM4.3Agents are able to list customer user emails without required permissions in the bulk action screen. This issue affects:...
CVE-2021-21442MEDIUM5.4In the project create screen it's possible to inject malicious JS code to the certain fields. The code might be executed...
CVE-2021-21440MEDIUM6.5Generated Support Bundles contains private S/MIME and PGP keys if containing folder is not hidden. This issue affects: O...
CVE-2021-37449MEDIUM5.4Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via /ogmlist?folder= (reflected).
CVE-2021-37448MEDIUM5.4Cross Site Scripting (XSS) exists in NCH IVM Attendant v5.12 and earlier via the Mailbox name (stored).
CVE-2021-37446MEDIUM4.3In NCH Quorum v2.03 and earlier, an authenticated user can use directory traversal via documentprop?file=/.. for file re...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now