2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-22741MEDIUM6.7Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxu...
CVE-2021-22740MEDIUM6.5Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause in...
CVE-2021-22739MEDIUM5.9Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a ...
CVE-2021-33469MEDIUM4.8COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter.
CVE-2021-20486MEDIUM6.5IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additio...
CVE-2021-20178MEDIUM5.5A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by th...
CVE-2021-27676MEDIUM5.4Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Desc...
CVE-2021-26034MEDIUM6.5An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data downl...
CVE-2021-26033MEDIUM6.5An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX r...
CVE-2021-26032MEDIUM6.1An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::c...
CVE-2021-29253MEDIUM5.5The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential st...
CVE-2021-29252MEDIUM5.4RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user...
CVE-2021-31924MEDIUM6.8Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, cou...
CVE-2021-33570MEDIUM5.4Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can ...
CVE-2021-32640MEDIUM5.3ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Pr...
CVE-2021-27562MEDIUM5.5In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the print...
CVE-2021-25935MEDIUM5.4In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2...
CVE-2021-25934MEDIUM5.4In OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2...
CVE-2021-32638MEDIUM4.4Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub a...
CVE-2021-29708MEDIUM6.7IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic ke...
CVE-2021-29695MEDIUM6.5IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker ...
CVE-2021-21660MEDIUM5.4Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cr...
CVE-2021-29211MEDIUM4.8A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrate...
CVE-2021-29210MEDIUM4.8A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380...
CVE-2021-29209MEDIUM4.8A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now