2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20105 | MEDIUM | 6.1 | 0.7% | Jun 29, 2021 | Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' p... |
| CVE-2021-20103 | MEDIUM | 6.1 | 0.7% | Jun 29, 2021 | Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attac... |
| CVE-2021-20101 | MEDIUM | 6.1 | 0.7% | Jun 29, 2021 | Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This ... |
| CVE-2021-31505 | MEDIUM | 6.8 | 0.6% | Jun 29, 2021 | This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus... |
| CVE-2021-29479 | MEDIUM | 6.1 | 0.9% | Jun 29, 2021 | Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied `X-Forwarded-Host` heade... |
| CVE-2021-28690 | MEDIUM | 6.5 | 1.0% | Jun 29, 2021 | x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vu... |
| CVE-2021-35303 | MEDIUM | 6.1 | 0.8% | Jun 28, 2021 | Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML v... |
| CVE-2021-35302 | MEDIUM | 5.3 | 1.2% | Jun 28, 2021 | Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive info... |
| CVE-2021-35301 | MEDIUM | 5.3 | 1.2% | Jun 28, 2021 | Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Tic... |
| CVE-2021-35300 | MEDIUM | 4.3 | 0.9% | Jun 28, 2021 | Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users... |
| CVE-2021-35298 | MEDIUM | 6.1 | 1.1% | Jun 28, 2021 | Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML v... |
| CVE-2021-32723 | MEDIUM | 6.5 | 1.4% | Jun 28, 2021 | Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Serv... |
| CVE-2021-32722 | MEDIUM | 6.5 | 1.3% | Jun 28, 2021 | GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an u... |
| CVE-2021-32720 | MEDIUM | 5.3 | 0.9% | Jun 28, 2021 | Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, par... |
| CVE-2021-35525 | MEDIUM | 5.3 | 1.6% | Jun 28, 2021 | PostSRSd before 1.11 allows a denial of service (subprocess hang) if Postfix sends certain long data fields such as mult... |
| CVE-2021-34254 | MEDIUM | 6.1 | 0.7% | Jun 28, 2021 | Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx. |
| CVE-2021-32719 | MEDIUM | 4.8 | 1.4% | Jun 28, 2021 | RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was di... |
| CVE-2021-29775 | MEDIUM | 5.4 | 0.9% | Jun 28, 2021 | IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerabl... |
| CVE-2021-29751 | MEDIUM | 4.3 | 0.9% | Jun 28, 2021 | IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authen... |
| CVE-2021-29693 | MEDIUM | 4.4 | 0.6% | Jun 28, 2021 | IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial ... |
| CVE-2021-20573 | MEDIUM | 6.5 | 1.5% | Jun 28, 2021 | IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bo... |
| CVE-2021-20572 | MEDIUM | 6.5 | 1.5% | Jun 28, 2021 | IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper b... |
| CVE-2021-20494 | MEDIUM | 6.5 | 1.1% | Jun 28, 2021 | IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bo... |
| CVE-2021-20413 | MEDIUM | 4.3 | 0.8% | Jun 28, 2021 | IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed... |
| CVE-2021-32718 | MEDIUM | 5.4 | 1.4% | Jun 28, 2021 | RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via ma... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now