2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32707 | MEDIUM | 4.3 | 1.1% | Jul 12, 2021 | Nextcloud Mail is a mail app for Nextcloud. In versions prior to 1.9.6, the Nextcloud Mail application does not, by defa... |
| CVE-2021-32689 | MEDIUM | 6.5 | 1.0% | Jul 12, 2021 | Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user... |
| CVE-2021-36381 | MEDIUM | 5.3 | 0.9% | Jul 12, 2021 | In Edifecs Transaction Management through 2021-07-12, an unauthenticated user can inject arbitrary text into a user's br... |
| CVE-2021-32703 | MEDIUM | 5.3 | 1.5% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the... |
| CVE-2021-29822 | MEDIUM | 5.4 | 0.5% | Jul 12, 2021 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2021-29805 | MEDIUM | 5.4 | 0.5% | Jul 12, 2021 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em... |
| CVE-2021-29804 | MEDIUM | 5.4 | 0.5% | Jul 12, 2021 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em... |
| CVE-2021-29803 | MEDIUM | 5.4 | 0.5% | Jul 12, 2021 | IBM Tivoli Netcool/OMNIbus_GUI 8.1.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to em... |
| CVE-2021-21591 | MEDIUM | 6.7 | 0.2% | Jul 12, 2021 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili... |
| CVE-2021-21590 | MEDIUM | 6.7 | 0.2% | Jul 12, 2021 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 contain a plain-text password storage vulnerabili... |
| CVE-2021-21589 | MEDIUM | 6.7 | 0.2% | Jul 12, 2021 | Dell EMC Unity, Unity XT, and UnityVSA versions prior to 5.1.0.0.5.394 do not exit on failed Initialization. A local aut... |
| CVE-2021-21588 | MEDIUM | 4.3 | 0.3% | Jul 12, 2021 | Dell EMC PowerFlex, v3.5.x contain a Cross-Site WebSocket Hijacking Vulnerability in the Presentation Server/WebUI. An u... |
| CVE-2021-20414 | MEDIUM | 4.9 | 0.5% | Jul 12, 2021 | IBM Guardium Data Encryption (GDE) 3.0.0.2 could allow a user to bruce force sensitive information due to not properly l... |
| CVE-2021-33037 | MEDIUM | 5.3 | 75.4% | Jul 12, 2021 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-enco... |
| CVE-2021-30640 | MEDIUM | 6.5 | 9.9% | Jul 12, 2021 | A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user n... |
| CVE-2021-36383 | MEDIUM | 4.3 | 0.7% | Jul 12, 2021 | Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by mod... |
| CVE-2021-24013 | MEDIUM | 6.5 | 1.1% | Jul 12, 2021 | Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unau... |
| CVE-2021-32678 | MEDIUM | 5.3 | 1.4% | Jul 12, 2021 | Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ra... |
| CVE-2021-30129 | MEDIUM | 6.5 | 3.4% | Jul 12, 2021 | A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error.... |
| CVE-2021-35037 | MEDIUM | 6.1 | 0.6% | Jul 12, 2021 | Jamf Pro before 10.30.1 allows for an unvalidated URL redirect vulnerability affecting Jamf Pro customers who host their... |
| CVE-2021-22918 | MEDIUM | 5.3 | 23.1% | Jul 12, 2021 | Node.js before 16.4.1, 14.17.2, 12.22.2 is vulnerable to an out-of-bounds read when uv__idna_toascii() is used to conver... |
| CVE-2021-22917 | MEDIUM | 6.5 | 1.2% | Jul 12, 2021 | Brave Browser Desktop between versions 1.17 and 1.20 is vulnerable to information disclosure by way of DNS requests in T... |
| CVE-2021-22916 | MEDIUM | 5.9 | 1.8% | Jul 12, 2021 | In Brave Desktop between versions 1.17 and 1.26.60, when adblocking is enabled and a proxy browser extension is installe... |
| CVE-2021-22515 | MEDIUM | 6.5 | 0.7% | Jul 12, 2021 | Multi-Factor Authentication (MFA) functionality can be bypassed, allowing the use of single factor authentication in Net... |
| CVE-2021-26099 | MEDIUM | 4.9 | 0.5% | Jul 12, 2021 | Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now