2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26080 | MEDIUM | 6.1 | 0.9% | Jun 7, 2021 | EditworkflowScheme.jspa in Jira Server and Jira Data Center before version 8.5.14, and from version 8.6.0 before version... |
| CVE-2021-26079 | MEDIUM | 6.1 | 0.9% | Jun 7, 2021 | The CardLayoutConfigTable component in Jira Server and Jira Data Center before version 8.5.15, and from version 8.6.0 be... |
| CVE-2021-26078 | MEDIUM | 6.1 | 3.8% | Jun 7, 2021 | The number range searcher component in Jira Server and Jira Data Center before version 8.5.14, from version 8.6.0 before... |
| CVE-2021-32670 | MEDIUM | 6.1 | 1.0% | Jun 7, 2021 | Datasette is an open source multi-tool for exploring and publishing data. The `?_trace=1` debugging feature in Datasette... |
| CVE-2021-30540 | MEDIUM | 6.5 | 1.4% | Jun 7, 2021 | Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform... |
| CVE-2021-30539 | MEDIUM | 5.4 | 1.3% | Jun 7, 2021 | Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac... |
| CVE-2021-30538 | MEDIUM | 4.3 | 15.7% | Jun 7, 2021 | Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac... |
| CVE-2021-30537 | MEDIUM | 4.3 | 1.1% | Jun 7, 2021 | Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass co... |
| CVE-2021-30534 | MEDIUM | 6.5 | 1.2% | Jun 7, 2021 | Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to byp... |
| CVE-2021-30533 | MEDIUM | 6.5 | 16.6% | Jun 7, 2021 | Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypa... |
| CVE-2021-30532 | MEDIUM | 4.3 | 1.2% | Jun 7, 2021 | Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac... |
| CVE-2021-30531 | MEDIUM | 6.5 | 1.7% | Jun 7, 2021 | Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attac... |
| CVE-2021-33896 | MEDIUM | 5.3 | 1.8% | Jun 7, 2021 | Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded pat... |
| CVE-2021-29621 | MEDIUM | 5.3 | 3.4% | Jun 7, 2021 | Flask-AppBuilder is a development framework, built on top of Flask. User enumeration in database authentication in Flask... |
| CVE-2021-33904 | MEDIUM | 6.1 | 10.1% | Jun 7, 2021 | In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The... |
| CVE-2021-29099 | MEDIUM | 5.3 | 0.6% | Jun 7, 2021 | A SQL injection vulnerability exists in some configurations of ArcGIS Server versions 10.8.1 and earlier. Specially craf... |
| CVE-2021-24344 | MEDIUM | 4.8 | 0.5% | Jun 7, 2021 | The Easy Preloader WordPress plugin through 1.0.0 does not sanitise its setting fields, leading to authenticated (admin+... |
| CVE-2021-24343 | MEDIUM | 4.8 | 0.6% | Jun 7, 2021 | The iFlyChat WordPress plugin before 4.7.0 does not sanitise its APP ID setting before outputting it back in the page, l... |
| CVE-2021-24342 | MEDIUM | 6.1 | 2.0% | Jun 7, 2021 | The JNews WordPress theme before 8.0.6 did not sanitise the cat_id parameter in the POST request /?ajax-request=jnews (w... |
| CVE-2021-28382 | MEDIUM | 5.4 | 1.2% | Jun 7, 2021 | Zoho ManageEngine Key Manager Plus before 6001 allows Stored XSS on the user-management page while importing malicious u... |
| CVE-2021-33881 | MEDIUM | 4.2 | 0.4% | Jun 6, 2021 | On NXP MIFARE Ultralight and NTAG cards, an attacker can interrupt a write operation (aka conduct a "tear off" attack) o... |
| CVE-2021-33880 | MEDIUM | 5.9 | 2.3% | Jun 6, 2021 | The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic A... |
| CVE-2021-32641 | MEDIUM | 6.1 | 1.5% | Jun 4, 2021 | auth0-lock is Auth0's signin solution. Versions of nauth0-lock before and including `11.30.0` are vulnerable to reflecte... |
| CVE-2021-31252 | MEDIUM | 6.1 | 28.6% | Jun 4, 2021 | An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices f... |
| CVE-2021-31250 | MEDIUM | 5.4 | 79.6% | Jun 4, 2021 | Multiple storage XSS vulnerabilities were discovered on BF-430, BF-431 and BF-450M TCP/IP Converter devices from CHIYU T... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now