2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29676 | MEDIUM | 5.4 | 0.8% | Jun 25, 2021 | IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victi... |
| CVE-2021-20583 | MEDIUM | 4.9 | 0.9% | Jun 25, 2021 | IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP G... |
| CVE-2021-32702 | MEDIUM | 6.1 | 1.4% | Jun 25, 2021 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and inc... |
| CVE-2021-3314 | MEDIUM | 6.1 | 0.9% | Jun 25, 2021 | Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an adm... |
| CVE-2021-35501 | MEDIUM | 5.4 | 1.0% | Jun 25, 2021 | PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an admini... |
| CVE-2021-31615 | MEDIUM | 5.3 | 0.4% | Jun 25, 2021 | Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent ... |
| CVE-2021-35475 | MEDIUM | 5.4 | 0.9% | Jun 25, 2021 | SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when e... |
| CVE-2021-32716 | MEDIUM | 4.9 | 1.1% | Jun 24, 2021 | Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidd... |
| CVE-2021-32713 | MEDIUM | 4.8 | 0.7% | Jun 24, 2021 | Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in admin... |
| CVE-2021-32712 | MEDIUM | 5.3 | 1.1% | Jun 24, 2021 | Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in ... |
| CVE-2021-32709 | MEDIUM | 4.9 | 0.6% | Jun 24, 2021 | Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users... |
| CVE-2021-29777 | MEDIUM | 6.5 | 1.4% | Jun 24, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circum... |
| CVE-2021-20579 | MEDIUM | 6.5 | 1.1% | Jun 24, 2021 | IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who... |
| CVE-2021-21571 | MEDIUM | 6.5 | 0.6% | Jun 24, 2021 | Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper ce... |
| CVE-2021-33348 | MEDIUM | 6.1 | 0.6% | Jun 24, 2021 | An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal fram... |
| CVE-2021-23398 | MEDIUM | 6.1 | 1.3% | Jun 24, 2021 | All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter.... |
| CVE-2021-29965 | MEDIUM | 5.3 | 0.7% | Jun 24, 2021 | A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to... |
| CVE-2021-29963 | MEDIUM | 4.3 | 0.3% | Jun 24, 2021 | Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affe... |
| CVE-2021-29962 | MEDIUM | 4.3 | 0.7% | Jun 24, 2021 | Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affe... |
| CVE-2021-29961 | MEDIUM | 4.3 | 0.8% | Jun 24, 2021 | When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an atta... |
| CVE-2021-29960 | MEDIUM | 4.3 | 0.8% | Jun 24, 2021 | Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usual... |
| CVE-2021-29959 | MEDIUM | 4.3 | 0.8% | Jun 24, 2021 | When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prev... |
| CVE-2021-29958 | MEDIUM | 4.3 | 0.7% | Jun 24, 2021 | When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to ... |
| CVE-2021-29957 | MEDIUM | 4.3 | 0.9% | Jun 24, 2021 | If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unp... |
| CVE-2021-29956 | MEDIUM | 4.3 | 0.8% | Jun 24, 2021 | OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now