2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-26080MEDIUM6.1EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version...
CVE-2021-26079MEDIUM6.1The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 be...
CVE-2021-26078MEDIUM6.1The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before...
CVE-2021-32670MEDIUM6.1Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette...
CVE-2021-30540MEDIUM6.5Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform...
CVE-2021-30539MEDIUM5.4Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac...
CVE-2021-30538MEDIUM4.3Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac...
CVE-2021-30537MEDIUM4.3Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass co...
CVE-2021-30534MEDIUM6.5Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to byp...
CVE-2021-30533MEDIUM6.5Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypa...
CVE-2021-30532MEDIUM4.3Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac...
CVE-2021-30531MEDIUM6.5Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac...
CVE-2021-33896MEDIUM5.3Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded pat...
CVE-2021-29621MEDIUM5.3Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask...
CVE-2021-33904MEDIUM6.1In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The...
CVE-2021-29099MEDIUM5.3A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially craf...
CVE-2021-24344MEDIUM4.8The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+...
CVE-2021-24343MEDIUM4.8The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, l...
CVE-2021-24342MEDIUM6.1The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (w...
CVE-2021-28382MEDIUM5.4Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious u...
CVE-2021-33881MEDIUM4.2On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) o...
CVE-2021-33880MEDIUM5.9The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic A...
CVE-2021-32641MEDIUM6.1auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflecte...
CVE-2021-31252MEDIUM6.1An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices f...
CVE-2021-31250MEDIUM5.4Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU T...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now