2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-36130MEDIUM4.8An XSS issue was discovered in the SocialProfile extension in MediaWiki through 1.36. Within several gift-related specia...
CVE-2021-36129MEDIUM4.3An issue was discovered in the Translate extension in MediaWiki through 1.36. The Aggregategroups Action API module does...
CVE-2021-36127MEDIUM4.3An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalUserRights page provid...
CVE-2021-27455MEDIUM5.5Delta Electronics DOPSoft Versions 4.0.10.17 and prior are vulnerable to an out-of-bounds read while processing project ...
CVE-2021-26920MEDIUM6.5In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP In...
CVE-2021-32731MEDIUM5.3XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Between (and in...
CVE-2021-32730MEDIUM5.7XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A cross-site re...
CVE-2021-32729MEDIUM5.4XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. A vulnerability...
CVE-2021-28424MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated u...
CVE-2021-35337MEDIUM4.3Sourcecodester Phone Shop Sales Managements System 1.0 is vulnerable to Insecure Direct Object Reference (IDOR). Any att...
CVE-2021-31813MEDIUM5.4Zoho ManageEngine Applications Manager before 15130 is vulnerable to Stored XSS while importing malicious user details (...
CVE-2021-22344MEDIUM5.3There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability ma...
CVE-2021-22347MEDIUM5.3There is an Improper Access Control vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability ma...
CVE-2021-20752MEDIUM6.1Cross-site scripting vulnerability in IkaIka RSS Reader all versions allows a remote attacker to inject an arbitrary scr...
CVE-2021-36083MEDIUM5.5KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE.
CVE-2021-28803MEDIUM5.4This issue affects: QNAP Systems Inc. Q'center versions prior to 1.11.1004.
CVE-2021-22346MEDIUM5.3There is an Improper Permission Management Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerabi...
CVE-2021-34075MEDIUM5.9In Artica Pandora FMS <=754 in the File Manager component, there is sensitive information exposed on the client side whi...
CVE-2021-21676MEDIUM4.3Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attac...
CVE-2021-21675MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers ...
CVE-2021-21674MEDIUM4.3A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permis...
CVE-2021-21673MEDIUM6.1Jenkins CAS Plugin 1.6.0 and earlier improperly determines that a redirect URL after login is legitimately pointing to J...
CVE-2021-21672MEDIUM4.3Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XX...
CVE-2021-21670MEDIUM4.3Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which...
CVE-2021-3630MEDIUM5.5An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djv...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now