2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29676MEDIUM5.4IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) is vulnerable to link injection. By persuading a victi...
CVE-2021-20583MEDIUM4.9IBM Security Verify (IBM Security Verify Privilege Vault 10.9.66) could disclose sensitive information through an HTTP G...
CVE-2021-32702MEDIUM6.1The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions before and inc...
CVE-2021-3314MEDIUM6.1Oracle GlassFish Server 3.1.2.18 and below allows /common/logViewer/logViewer.jsf XSS. A malicious user can cause an adm...
CVE-2021-35501MEDIUM5.4PandoraFMS <=7.54 allows Stored XSS by placing a payload in the name field of a visual console. When a user or an admini...
CVE-2021-31615MEDIUM5.3Unencrypted Bluetooth Low Energy baseband links in Bluetooth Core Specifications 4.0 through 5.2 may permit an adjacent ...
CVE-2021-35475MEDIUM5.4SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when e...
CVE-2021-32716MEDIUM4.9Shopware is an open source eCommerce platform. In versions prior to 6.4.1.1 the admin api has exposed some internal hidd...
CVE-2021-32713MEDIUM4.8Shopware is an open source eCommerce platform. Versions prior to 5.6.10 suffer from an authenticated stored XSS in admin...
CVE-2021-32712MEDIUM5.3Shopware is an open source eCommerce platform. Versions prior to 5.6.10 are vulnerable to system information leakage in ...
CVE-2021-32709MEDIUM4.9Shopware is an open source eCommerce platform. Creation of order credits was not validated by ACL in admin orders. Users...
CVE-2021-29777MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5, under specific circum...
CVE-2021-20579MEDIUM6.5IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user who...
CVE-2021-21571MEDIUM6.5Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper ce...
CVE-2021-33348MEDIUM6.1An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal fram...
CVE-2021-23398MEDIUM6.1All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter....
CVE-2021-29965MEDIUM5.3A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built-in password manager to...
CVE-2021-29963MEDIUM4.3Address bar search suggestions in private browsing mode were re-using session data from normal mode. *This bug only affe...
CVE-2021-29962MEDIUM4.3Firefox for Android would become unstable and hard-to-recover when a website opened too many popups. *This bug only affe...
CVE-2021-29961MEDIUM4.3When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an atta...
CVE-2021-29960MEDIUM4.3Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usual...
CVE-2021-29959MEDIUM4.3When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prev...
CVE-2021-29958MEDIUM4.3When a download was initiated, the client did not check whether it was in normal or private browsing mode, which led to ...
CVE-2021-29957MEDIUM4.3If a MIME encoded email contains an OpenPGP inline signed or encrypted message part, but also contains an additional unp...
CVE-2021-29956MEDIUM4.3OpenPGP secret keys that were imported using Thunderbird version 78.8.1 up to version 78.10.1 were stored unencrypted on...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now