2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-31184MEDIUM5.5Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability
CVE-2021-31178MEDIUM5.5Microsoft Office Information Disclosure Vulnerability
CVE-2021-31174MEDIUM5.5Microsoft Excel Information Disclosure Vulnerability
CVE-2021-31173MEDIUM5.3Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2021-31171MEDIUM4.1Microsoft SharePoint Information Disclosure Vulnerability
CVE-2021-28479MEDIUM5.5Windows CSC Service Information Disclosure Vulnerability
CVE-2021-28461MEDIUM6.1Dynamics Finance and Operations Cross-site Scripting Vulnerability
CVE-2021-26421MEDIUM6.5Skype for Business and Lync Spoofing Vulnerability
CVE-2021-26418MEDIUM4.6Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-32573MEDIUM4.8The express-cart package through 1.1.10 for Node.js allows Reflected XSS (for an admin) via a user input field for produ...
CVE-2021-31537MEDIUM6.1SIS SIS-REWE Go before 7.7 SP17 allows XSS: rewe/prod/web/index.php (affected parameters are config, version, win, db, p...
CVE-2021-29471MEDIUM5.3Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for ope...
CVE-2021-27619MEDIUM6.5SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for at...
CVE-2021-27618MEDIUM4.9The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does n...
CVE-2021-27617MEDIUM4.9The Integration Builder Framework of SAP Process Integration versions - 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does n...
CVE-2021-27612MEDIUM6.1In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious...
CVE-2021-27611MEDIUM6.7SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by ...
CVE-2021-21654MEDIUM4.3Jenkins P4 Plugin 1.11.4 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers w...
CVE-2021-21653MEDIUM4.3Jenkins Xray - Test Management for Jira Plugin 2.4.0 and earlier does not perform a permission check in an HTTP endpoint...
CVE-2021-21651MEDIUM4.3Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform a permission check in an HTTP endpoint, allowing attacke...
CVE-2021-21650MEDIUM4.3Jenkins S3 publisher Plugin 0.11.6 and earlier does not perform Run/Artifacts permission checks in various HTTP endpoint...
CVE-2021-21649MEDIUM5.4Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in...
CVE-2021-21648MEDIUM6.1Jenkins Credentials Plugin 2.3.18 and earlier does not escape user-controlled information on a view it provides, resulti...
CVE-2021-32561MEDIUM6.1OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.
CVE-2021-32560MEDIUM6.5The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that ar...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now