2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-36130 | MEDIUM | 4.8 | 0.5% | Jul 2, 2021 | An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related specia... |
| CVE-2021-36129 | MEDIUM | 4.3 | 0.6% | Jul 2, 2021 | An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does... |
| CVE-2021-36127 | MEDIUM | 4.3 | 0.7% | Jul 2, 2021 | An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provid... |
| CVE-2021-27455 | MEDIUM | 5.5 | 0.7% | Jul 2, 2021 | Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project ... |
| CVE-2021-26920 | MEDIUM | 6.5 | 9.5% | Jul 2, 2021 | In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP In... |
| CVE-2021-32731 | MEDIUM | 5.3 | 1.2% | Jul 1, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and in... |
| CVE-2021-32730 | MEDIUM | 5.7 | 0.6% | Jul 1, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site re... |
| CVE-2021-32729 | MEDIUM | 5.4 | 0.5% | Jul 1, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability... |
| CVE-2021-28424 | MEDIUM | 5.4 | 1.3% | Jul 1, 2021 | A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated u... |
| CVE-2021-35337 | MEDIUM | 4.3 | 0.8% | Jul 1, 2021 | Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any att... |
| CVE-2021-31813 | MEDIUM | 5.4 | 78.3% | Jul 1, 2021 | Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (... |
| CVE-2021-22344 | MEDIUM | 5.3 | 0.7% | Jul 1, 2021 | There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability ma... |
| CVE-2021-22347 | MEDIUM | 5.3 | 0.7% | Jul 1, 2021 | There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability ma... |
| CVE-2021-20752 | MEDIUM | 6.1 | 0.8% | Jul 1, 2021 | Cross-site scripting vulnerability in IkaIka RSS Reader all versions allows a remote attacker to inject an arbitrary scr... |
| CVE-2021-36083 | MEDIUM | 5.5 | 0.9% | Jul 1, 2021 | KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE. |
| CVE-2021-28803 | MEDIUM | 5.4 | 0.5% | Jul 1, 2021 | This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004. |
| CVE-2021-22346 | MEDIUM | 5.3 | 0.5% | Jun 30, 2021 | There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerabi... |
| CVE-2021-34075 | MEDIUM | 5.9 | 0.9% | Jun 30, 2021 | In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side whi... |
| CVE-2021-21676 | MEDIUM | 4.3 | 1.4% | Jun 30, 2021 | Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attac... |
| CVE-2021-21675 | MEDIUM | 6.5 | 1.3% | Jun 30, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers ... |
| CVE-2021-21674 | MEDIUM | 4.3 | 1.0% | Jun 30, 2021 | A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permis... |
| CVE-2021-21673 | MEDIUM | 6.1 | 1.6% | Jun 30, 2021 | Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to J... |
| CVE-2021-21672 | MEDIUM | 4.3 | 42.5% | Jun 30, 2021 | Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XX... |
| CVE-2021-21670 | MEDIUM | 4.3 | 2.0% | Jun 30, 2021 | Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which... |
| CVE-2021-3630 | MEDIUM | 5.5 | 1.1% | Jun 30, 2021 | An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djv... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now