2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21666MEDIUM6.1Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpo...
CVE-2021-21664MEDIUM6.5An incorrect permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Generic Cre...
CVE-2021-21663MEDIUM4.3A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 7.5.8 and earlier allows attackers with Overall/Read pe...
CVE-2021-21662MEDIUM4.3A missing permission check in Jenkins XebiaLabs XL Deploy Plugin 10.0.1 and earlier allows attackers with Overall/Read p...
CVE-2021-21661MEDIUM4.3Jenkins Kubernetes CLI Plugin 1.10.0 and earlier does not perform permission checks in several HTTP endpoints, allowing ...
CVE-2021-31929MEDIUM4.3Annex Cloud Loyalty Experience Platform <2021.1.0.1 allows any authenticated attacker to modify loyalty campaigns and se...
CVE-2021-21735MEDIUM6.5A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user...
CVE-2021-20293MEDIUM6.1A reflected Cross-Site Scripting (XSS) flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final, where i...
CVE-2021-30641MEDIUM5.3Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
CVE-2021-0134MEDIUM4.9Improper input validation in an API for the Intel(R) Security Library before version 3.3 may allow a privileged user to ...
CVE-2021-0132MEDIUM4.9Missing release of resource after effective lifetime in an API for the Intel(R) Security Library before version 3.3 may ...
CVE-2021-0131MEDIUM6.5Use of cryptographically weak pseudo-random number generator (PRNG) in an API for the Intel(R) Security Library before v...
CVE-2021-0129MEDIUM5.7Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjace...
CVE-2021-0089MEDIUM6.5Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable informati...
CVE-2021-0086MEDIUM6.5Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user t...
CVE-2021-0067MEDIUM6.7&nbsp;Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enabl...
CVE-2021-0054MEDIUM6.7Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable...
CVE-2021-0051MEDIUM4.4Improper input validation in the Intel(R) SPS versions before SPS_E5_04.04.04.023.0, SPS_E5_04.04.03.228.0 or SPS_SoC-A_...
CVE-2021-0001MEDIUM4.7Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enab...
CVE-2021-29049MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Portal Workflow module's edit process page in Liferay DXP 7.0 before fix...
CVE-2021-0113MEDIUM6.5Out of bounds write in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08...
CVE-2021-0097MEDIUM6.5Path traversal in the BMC firmware for Intel(R) Server Board M10JNP2SB before version EFI BIOS 7215, BMC 8100.01.08 may ...
CVE-2021-0095MEDIUM4.4Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a...
CVE-2021-32942MEDIUM5.5The vulnerability could expose cleartext credentials from AVEVA InTouch Runtime 2020 R2 and all prior versions (WindowVi...
CVE-2021-30133MEDIUM6.1A cross-site scripting (XSS) vulnerability in CloverDX Server 5.9.0, CloverDX 5.8.1, CloverDX 5.7.0, and earlier allows ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now