2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-32707MEDIUM4.3Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by defa...
CVE-2021-32689MEDIUM6.5Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user...
CVE-2021-36381MEDIUM5.3In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's br...
CVE-2021-32703MEDIUM5.3Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the...
CVE-2021-29822MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2021-29805MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em...
CVE-2021-29804MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em...
CVE-2021-29803MEDIUM5.4IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em...
CVE-2021-21591MEDIUM6.7Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili...
CVE-2021-21590MEDIUM6.7Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili...
CVE-2021-21589MEDIUM6.7Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local aut...
CVE-2021-21588MEDIUM4.3Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An u...
CVE-2021-20414MEDIUM4.9IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly l...
CVE-2021-33037MEDIUM5.3Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-enco...
CVE-2021-30640MEDIUM6.5A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user n...
CVE-2021-36383MEDIUM4.3Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by mod...
CVE-2021-24013MEDIUM6.5Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unau...
CVE-2021-32678MEDIUM5.3Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ra...
CVE-2021-30129MEDIUM6.5A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error....
CVE-2021-35037MEDIUM6.1Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their...
CVE-2021-22918MEDIUM5.3Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to conver...
CVE-2021-22917MEDIUM6.5Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in T...
CVE-2021-22916MEDIUM5.9In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installe...
CVE-2021-22515MEDIUM6.5Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in Net...
CVE-2021-26099MEDIUM4.9Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now