2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29554MEDIUM5.5TensorFlow is an end-to-end open source platform for machine learning. An attacker can cause a denial of service via a F...
CVE-2021-20565MEDIUM5.3IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 uses a protection mechanism that relie...
CVE-2021-20564MEDIUM5.9IBM Cloud Pak for Security (CP4S) 1.4.0.0, 1.5.0.0, 1.5.0.1, 1.6.0.0, and 1.6.0.1 could allow a remote attacker to obtai...
CVE-2021-20429MEDIUM5.3IBM QRadar User Behavior Analytics 1.0.0 through 4.1.0 could disclose sensitive information due an overly permissive cro...
CVE-2021-20392MEDIUM6.1IBM QRadar User Behavior Analytics 1.0.0 through 4.0.1 is vulnerable to cross-site scripting. This vulnerability allows ...
CVE-2021-32613MEDIUM5.5In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
CVE-2021-24291MEDIUM6.1The Photo Gallery by 10Web – Mobile-Friendly Image Gallery WordPress plugin before 1.5.69 was vulnerable to Reflected Cr...
CVE-2021-24287MEDIUM6.1The settings page of the Select All Categories and Taxonomies, Change Checkbox to Radio Buttons WordPress plugin before ...
CVE-2021-24286MEDIUM6.1The settings page of the Redirect 404 to parent WordPress plugin before 1.3.1 did not properly sanitise the tab paramete...
CVE-2021-24283MEDIUM5.4The tab GET parameter of the settings page is not sanitised or escaped when being output back in an HTML attribute, lead...
CVE-2021-24282MEDIUM6.3In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could...
CVE-2021-24281MEDIUM4.3In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, any authenticated user, such as a subscriber, could...
CVE-2021-24279MEDIUM6.5In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the...
CVE-2021-24277MEDIUM5.4The RSS for Yandex Turbo WordPress plugin before 1.30 did not properly sanitise the user inputs from its Счетчики settin...
CVE-2021-31876MEDIUM6.5Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes i...
CVE-2021-29506MEDIUM6.5GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a re...
CVE-2021-23906MEDIUM6.8An issue was discovered in the Headunit NTG6 in the MBUX Infotainment System on Mercedes-Benz vehicles through 2021. A M...
CVE-2021-32925MEDIUM6.5admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
CVE-2021-22139MEDIUM6.5Kibana versions before 7.12.1 contain a denial of service vulnerability was found in the webhook actions due to a lack o...
CVE-2021-22137MEDIUM5.3In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Sec...
CVE-2021-22135MEDIUM5.3Elasticsearch versions before 7.11.2 and 6.8.15 contain a document disclosure flaw was found in the Elasticsearch sugges...
CVE-2021-32921MEDIUM5.9An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret...
CVE-2021-32917MEDIUM5.3An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither o...
CVE-2021-21424MEDIUM5.3Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumera...
CVE-2021-20535MEDIUM5.4IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now