2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-20105MEDIUM6.1Machform prior to version 16 is vulnerable to an open redirect in Safari_init.php due to an improperly sanitized 'ref' p...
CVE-2021-20103MEDIUM6.1Machform prior to version 16 is vulnerable to stored cross-site scripting due to insufficient sanitization of file attac...
CVE-2021-20101MEDIUM6.1Machform prior to version 16 is vulnerable to HTTP host header injection due to improperly validated host headers. This ...
CVE-2021-31505MEDIUM6.8This vulnerability allows attackers with physical access to escalate privileges on affected installations of Arlo Q Plus...
CVE-2021-29479MEDIUM6.1Ratpack is a toolkit for creating web applications. In versions prior to 1.9.0, a user supplied `X-Forwarded-Host` heade...
CVE-2021-28690MEDIUM6.5x86: TSX Async Abort protections not restored after S3 This issue relates to the TSX Async Abort speculative security vu...
CVE-2021-35303MEDIUM6.1Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML v...
CVE-2021-35302MEDIUM5.3Incorrect Access Control for linked Tickets in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive info...
CVE-2021-35301MEDIUM5.3Incorrect Access Control in Zammad 1.0.x up to 4.0.0 allows remote attackers to obtain sensitive information via the Tic...
CVE-2021-35300MEDIUM4.3Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote attackers to manipulate users...
CVE-2021-35298MEDIUM6.1Cross Site Scripting (XSS) in Zammad 1.0.x up to 4.0.0 allows remote attackers to execute arbitrary web script or HTML v...
CVE-2021-32723MEDIUM6.5Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Serv...
CVE-2021-32722MEDIUM6.5GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an u...
CVE-2021-32720MEDIUM5.3Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, par...
CVE-2021-35525MEDIUM5.3PostSRSd before 1.11 allows a denial of service (subprocess hang) if Postfix sends certain long data fields such as mult...
CVE-2021-34254MEDIUM6.1Umbraco CMS before 7.15.7 is vulnerable to Open Redirection due to insufficient url sanitization on booting.aspx.
CVE-2021-32719MEDIUM4.8RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.18, when a federation link was di...
CVE-2021-29775MEDIUM5.4IBM Business Automation Workflow 19.0.03 and 20.0 and IBM Cloud Pak for Automation 20.0.3-IF002 and 21.0.1 are vulnerabl...
CVE-2021-29751MEDIUM4.3IBM Business Automation Workflow 18.0, 19.0, and 20.0 and IBM Business Process Manager 8.5 and 8.6 could allow an authen...
CVE-2021-29693MEDIUM4.4IBM AIX 7.1, 7.2, and VIOS 3.1 could allow a local user that is in the with elevated group privileges to cause a denial ...
CVE-2021-20573MEDIUM6.5IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap-based buffer overflow, caused by improper bo...
CVE-2021-20572MEDIUM6.5IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a stack-based buffer overflow, caused by improper b...
CVE-2021-20494MEDIUM6.5IBM Security Identity Manager Adapters 6.0 and 7.0 are vulnerable to a heap based buffer overflow, caused by improper bo...
CVE-2021-20413MEDIUM4.3IBM Guardium Data Encryption (GDE) 4.0.0.4 could allow a remote attacker to obtain sensitive information when a detailed...
CVE-2021-32718MEDIUM5.4RabbitMQ is a multi-protocol messaging broker. In rabbitmq-server prior to version 3.8.17, a new user being added via ma...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now