2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-32511 | MEDIUM | 4.3 | 0.9% | Jul 7, 2021 | QSAN Storage Manager through directory listing vulnerability in ViewBroserList allows remote authenticated attackers to ... |
| CVE-2021-32510 | MEDIUM | 4.3 | 0.9% | Jul 7, 2021 | QSAN Storage Manager through directory listing vulnerability in antivirus function allows remote authenticated attackers... |
| CVE-2021-32509 | MEDIUM | 6.5 | 1.3% | Jul 7, 2021 | Absolute Path Traversal vulnerability in FileviewDoc in QSAN Storage Manager allows remote authenticated attackers acces... |
| CVE-2021-32508 | MEDIUM | 6.5 | 1.3% | Jul 7, 2021 | Absolute Path Traversal vulnerability in FileStreaming in QSAN Storage Manager allows remote authenticated attackers acc... |
| CVE-2021-32507 | MEDIUM | 6.5 | 1.3% | Jul 7, 2021 | Absolute Path Traversal vulnerability in FileDownload in QSAN Storage Manager allows remote authenticated attackers down... |
| CVE-2021-32506 | MEDIUM | 6.5 | 1.3% | Jul 7, 2021 | Absolute Path Traversal vulnerability in GetImage in QSAN Storage Manager allows remote authenticated attackers download... |
| CVE-2021-22233 | MEDIUM | 4.3 | 0.8% | Jul 7, 2021 | An information disclosure vulnerability in GitLab EE versions 13.10 and later allowed a user to read project details |
| CVE-2021-36212 | MEDIUM | 6.1 | 0.6% | Jul 7, 2021 | app/View/SharingGroups/view.ctp in MISP before 2.4.146 allows stored XSS in the sharing groups view. |
| CVE-2021-34627 | MEDIUM | 4.3 | 0.7% | Jul 7, 2021 | A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-leve... |
| CVE-2021-34626 | MEDIUM | 4.3 | 0.7% | Jul 7, 2021 | A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenti... |
| CVE-2021-34625 | MEDIUM | 5.4 | 0.6% | Jul 7, 2021 | A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authentica... |
| CVE-2021-22225 | MEDIUM | 5.4 | 0.6% | Jul 7, 2021 | Insufficient input sanitization in markdown in GitLab version 13.11 and up allows an attacker to exploit a stored cross-... |
| CVE-2021-22224 | MEDIUM | 6.5 | 0.9% | Jul 7, 2021 | A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 ... |
| CVE-2021-26039 | MEDIUM | 6.1 | 0.9% | Jul 7, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the imagelist view of com_media leads to... |
| CVE-2021-26037 | MEDIUM | 5.3 | 1.0% | Jul 7, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions w... |
| CVE-2021-26035 | MEDIUM | 6.1 | 0.9% | Jul 7, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads t... |
| CVE-2021-22231 | MEDIUM | 4.3 | 1.0% | Jul 7, 2021 | A denial of service in user's profile page is found starting with GitLab CE/EE 8.0 that allows attacker to reject access... |
| CVE-2021-22227 | MEDIUM | 6.1 | 0.9% | Jul 7, 2021 | A reflected cross-site script vulnerability in GitLab before versions 13.11.6, 13.12.6 and 14.0.2 allowed an attacker to... |
| CVE-2021-20777 | MEDIUM | 4.3 | 0.9% | Jul 7, 2021 | Improper authorization in handler for custom URL scheme vulnerability in GU App for Android versions from 4.8.0 to 5.0.2... |
| CVE-2021-20738 | MEDIUM | 6.5 | 0.4% | Jul 7, 2021 | WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain se... |
| CVE-2021-22228 | MEDIUM | 6.5 | 1.4% | Jul 6, 2021 | An issue has been discovered in GitLab affecting all versions before 13.11.6, all versions starting from 13.12 before 13... |
| CVE-2021-22223 | MEDIUM | 6.1 | 0.9% | Jul 6, 2021 | Client-Side code injection through Feature Flag name in GitLab CE/EE starting with 11.9 allows a specially crafted featu... |
| CVE-2021-22232 | MEDIUM | 5.4 | 0.7% | Jul 6, 2021 | HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE |
| CVE-2021-22226 | MEDIUM | 6.5 | 0.9% | Jul 6, 2021 | Under certain conditions, some users were able to push to protected branches that were restricted to deploy keys in GitL... |
| CVE-2021-34190 | MEDIUM | 4.8 | 0.6% | Jul 6, 2021 | A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attack... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now