2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-20306MEDIUM4.3A flaw was found in the BPMN editor in version jBPM 7.51.0.Final. Any authenticated user from any project can see the na...
CVE-2021-23021MEDIUM5.5The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with c...
CVE-2021-23020MEDIUM5.5The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which co...
CVE-2021-25932MEDIUM5.4In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation...
CVE-2021-32635MEDIUM6.3Singularity is an open source container platform. In verions 3.7.2 and 3.7.3, Dde to incorrect use of a default URL, `si...
CVE-2021-32616MEDIUM6.11CDN is open-source file sharing software. In 1CDN before commit f88a2730fa50fc2c2aeab09011f6f142fd90ec25, there is a ba...
CVE-2021-29507MEDIUM6.5GENIVI Diagnostic Log and Trace (DLT) provides a log and trace interface. In versions of GENIVI DLT between 2.10.0 and 2...
CVE-2021-3514MEDIUM6.5When using a sync_repl client in 389-ds-base, an authenticated attacker can cause a NULL pointer dereference using a spe...
CVE-2021-33620MEDIUM6.5Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all...
CVE-2021-21734MEDIUM6.5Some PON MDU devices of ZTE stored sensitive information in plaintext, and users with login authority can obtain it by i...
CVE-2021-20292MEDIUM6.7There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouvea...
CVE-2021-20278MEDIUM6.5An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `Op...
CVE-2021-20201MEDIUM5.3A flaw was found in spice in versions before 0.14.92. A DoS tool might make it easier for remote attackers to cause a de...
CVE-2021-32543MEDIUM5.4The CTS Web transaction system related to authentication management is implemented incorrectly. After login, remote atta...
CVE-2021-32542MEDIUM6.1The parameters of the specific functions in the CTS Web trading system do not filter special characters, which allows un...
CVE-2021-32541MEDIUM5.3The CTS Web transaction system related to authentication and session management is implemented incorrectly, which allows...
CVE-2021-32540MEDIUM5.4Add announcement function in the 101EIP system does not filter special characters, which allows authenticated users to i...
CVE-2021-32539MEDIUM5.4Add event in calendar function in the 101EIP system does not filter special characters in specific fields, which allows ...
CVE-2021-33408MEDIUM6.5Local File Inclusion vulnerability in Ab Initio Control>Center before 4.0.2.6 allows remote attackers to retrieve arbitr...
CVE-2021-33394MEDIUM5.4Cubecart 6.4.2 allows Session Fixation. The application does not generate a new session cookie after the user is logged ...
CVE-2021-32643MEDIUM5.8Http4s is a Scala interface for HTTP services. `StaticFile.fromUrl` can leak the presence of a directory on a server whe...
CVE-2021-32645MEDIUM6.1Tenancy multi-tenant is an open source multi-domain controller for the Laravel web framework. In some situations, it is ...
CVE-2021-27492MEDIUM5.5When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, Catia...
CVE-2021-31808MEDIUM6.5An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a...
CVE-2021-31806MEDIUM6.5An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now