2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22741 | MEDIUM | 6.7 | 0.2% | May 26, 2021 | Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxu... |
| CVE-2021-22740 | MEDIUM | 6.5 | 0.8% | May 26, 2021 | Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause in... |
| CVE-2021-22739 | MEDIUM | 5.9 | 0.8% | May 26, 2021 | Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a ... |
| CVE-2021-33469 | MEDIUM | 4.8 | 0.7% | May 26, 2021 | COVID19 Testing Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the "Admin name" parameter. |
| CVE-2021-20486 | MEDIUM | 6.5 | 0.9% | May 26, 2021 | IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additio... |
| CVE-2021-20178 | MEDIUM | 5.5 | 0.3% | May 26, 2021 | A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by th... |
| CVE-2021-27676 | MEDIUM | 5.4 | 0.6% | May 26, 2021 | Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Desc... |
| CVE-2021-26034 | MEDIUM | 6.5 | 0.6% | May 26, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in data downl... |
| CVE-2021-26033 | MEDIUM | 6.5 | 0.6% | May 26, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.26. A missing token check causes a CSRF vulnerability in the AJAX r... |
| CVE-2021-26032 | MEDIUM | 6.1 | 1.0% | May 26, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.26. HTML was missing in the executable block list of MediaHelper::c... |
| CVE-2021-29253 | MEDIUM | 5.5 | 0.2% | May 26, 2021 | The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential st... |
| CVE-2021-29252 | MEDIUM | 5.4 | 0.8% | May 26, 2021 | RSA Archer before 6.9 SP1 P1 (6.9.1.1) contains a stored XSS vulnerability. A remote authenticated malicious Archer user... |
| CVE-2021-31924 | MEDIUM | 6.8 | 0.3% | May 26, 2021 | Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, cou... |
| CVE-2021-33570 | MEDIUM | 5.4 | 3.6% | May 25, 2021 | Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can ... |
| CVE-2021-32640 | MEDIUM | 5.3 | 2.9% | May 25, 2021 | ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Pr... |
| CVE-2021-27562 | MEDIUM | 5.5 | 3.1% | May 25, 2021 | In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the print... |
| CVE-2021-25935 | MEDIUM | 5.4 | 0.9% | May 25, 2021 | In OpenNMS Horizon, versions opennms-17.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2... |
| CVE-2021-25934 | MEDIUM | 5.4 | 1.0% | May 25, 2021 | In OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2... |
| CVE-2021-32638 | MEDIUM | 4.4 | 0.4% | May 25, 2021 | Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub a... |
| CVE-2021-29708 | MEDIUM | 6.7 | 0.3% | May 25, 2021 | IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic ke... |
| CVE-2021-29695 | MEDIUM | 6.5 | 2.3% | May 25, 2021 | IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker ... |
| CVE-2021-21660 | MEDIUM | 5.4 | 1.1% | May 25, 2021 | Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cr... |
| CVE-2021-29211 | MEDIUM | 4.8 | 0.6% | May 25, 2021 | A remote xss vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380 Gen9; HPE Integrate... |
| CVE-2021-29210 | MEDIUM | 4.8 | 0.5% | May 25, 2021 | A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380... |
| CVE-2021-29209 | MEDIUM | 4.8 | 0.5% | May 25, 2021 | A remote dom xss, crlf injection vulnerability was discovered in HPE Integrated Lights-Out 4 (iLO 4); HPE SimpliVity 380... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now