2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29503 | MEDIUM | 6.1 | 1.0% | May 19, 2021 | HedgeDoc is a platform to write and share markdown. HedgeDoc before version 1.8.2 is vulnerable to a cross-site scriptin... |
| CVE-2021-27924 | MEDIUM | 5.9 | 0.5% | May 19, 2021 | An issue was discovered in Couchbase Server 6.x through 6.6.1. The Couchbase Server UI is insecurely logging session coo... |
| CVE-2021-20529 | MEDIUM | 5.3 | 0.9% | May 19, 2021 | IBM Control Center 6.2.0.0 could allow a user to obtain sensitive version information that could be used in further atta... |
| CVE-2021-20528 | MEDIUM | 5.4 | 0.5% | May 19, 2021 | IBM Control Center 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2021-20374 | MEDIUM | 5.4 | 0.5% | May 19, 2021 | IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows user... |
| CVE-2021-31158 | MEDIUM | 6.5 | 0.7% | May 19, 2021 | In the Query Engine in Couchbase Server 6.5.x and 6.6.x through 6.6.1, Common Table Expression queries were not correctl... |
| CVE-2021-27925 | MEDIUM | 4.4 | 0.5% | May 19, 2021 | An issue was discovered in Couchbase Server 6.5.x and 6.6.x through 6.6.1. When using the View Engine and Auditing is en... |
| CVE-2021-31930 | MEDIUM | 6.1 | 0.9% | May 19, 2021 | Persistent cross-site scripting (XSS) in the web interface of Concerto through 2.3.6 allows an unauthenticated remote at... |
| CVE-2021-3421 | MEDIUM | 5.5 | 0.7% | May 19, 2021 | A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to... |
| CVE-2021-21733 | MEDIUM | 4.9 | 0.8% | May 19, 2021 | The management system of ZXCDN is impacted by the information leak vulnerability. Attackers can make further analysis ac... |
| CVE-2021-31323 | MEDIUM | 5.5 | 1.3% | May 18, 2021 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the... |
| CVE-2021-31322 | MEDIUM | 5.5 | 1.4% | May 18, 2021 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Heap Buffer Overflow in the... |
| CVE-2021-31319 | MEDIUM | 5.5 | 1.3% | May 18, 2021 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by an Integer Overflow in the LO... |
| CVE-2021-31318 | MEDIUM | 5.5 | 1.3% | May 18, 2021 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the LOTCo... |
| CVE-2021-31317 | MEDIUM | 5.5 | 1.3% | May 18, 2021 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Type Confusion in the VDash... |
| CVE-2021-31315 | MEDIUM | 5.5 | 1.3% | May 18, 2021 | Telegram Android <7.1.0 (2090), Telegram iOS <7.1, and Telegram macOS <7.1 are affected by a Stack Based Overflow in the... |
| CVE-2021-3531 | MEDIUM | 5.3 | 2.4% | May 18, 2021 | A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift U... |
| CVE-2021-29023 | MEDIUM | 5.3 | 0.8% | May 17, 2021 | InvoicePlane 1.5.11 doesn't have any rate-limiting for password reset and the reset token is generated using a weak mech... |
| CVE-2021-32618 | MEDIUM | 6.1 | 3.3% | May 17, 2021 | The Python "Flask-Security-Too" package is used for adding security features to your Flask application. It is an is an i... |
| CVE-2021-32617 | MEDIUM | 5.5 | 1.2% | May 17, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-32456 | MEDIUM | 6.5 | 0.3% | May 17, 2021 | SITEL CAP/PRX firmware version 5.2.01 allows an attacker with access to the local network of the device to obtain the au... |
| CVE-2021-23384 | MEDIUM | 5.4 | 0.8% | May 17, 2021 | The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slas... |
| CVE-2021-3524 | MEDIUM | 6.5 | 1.6% | May 17, 2021 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability... |
| CVE-2021-33041 | MEDIUM | 6.1 | 1.2% | May 17, 2021 | vmd through 1.34.0 allows 'div class="markdown-body"' XSS, as demonstrated by Electron remote code execution via require... |
| CVE-2021-32455 | MEDIUM | 6.5 | 0.4% | May 17, 2021 | SITEL CAP/PRX firmware version 5.2.01, allows an attacker with access to the device´s network to cause a denial of servi... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now