2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21990MEDIUM6.1VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior ...
CVE-2021-31911MEDIUM6.1In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages.
CVE-2021-3315MEDIUM5.4In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible.
CVE-2021-31908MEDIUM5.4In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages.
CVE-2021-31907MEDIUM5.3In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly.
CVE-2021-31904MEDIUM6.1In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page.
CVE-2021-31903MEDIUM6.1In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS.
CVE-2021-31900MEDIUM5.3In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host.
CVE-2021-27733MEDIUM5.4In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment.
CVE-2021-32544MEDIUM5.4Special characters of IGT search function in igt+ are not filtered in specific fields, which allow remote authenticated ...
CVE-2021-30174MEDIUM5.4RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filt...
CVE-2021-32489MEDIUM4.4An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not ...
CVE-2021-32053MEDIUM5.3JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attac...
CVE-2021-21430MEDIUM5.5OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configurat...
CVE-2021-29022MEDIUM5.3In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory.
CVE-2021-29502MEDIUM6.5WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to...
CVE-2021-29501MEDIUM6.5Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users t...
CVE-2021-20577MEDIUM6.1IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows u...
CVE-2021-20559MEDIUM5.4IBM Control Desk 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb...
CVE-2021-23016MEDIUM5.3On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 1...
CVE-2021-32056MEDIUM4.3Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access r...
CVE-2021-25645MEDIUM4.4An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An i...
CVE-2021-20717MEDIUM6.1Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted scri...
CVE-2021-3003MEDIUM5.3Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allo...
CVE-2021-31471MEDIUM5.5This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 1...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now