2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21990 | MEDIUM | 6.1 | 0.8% | May 11, 2021 | VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior ... |
| CVE-2021-31911 | MEDIUM | 6.1 | 0.7% | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, reflected XSS was possible on several pages. |
| CVE-2021-3315 | MEDIUM | 5.4 | 0.5% | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, stored XSS on a tests page was possible. |
| CVE-2021-31908 | MEDIUM | 5.4 | 0.5% | May 11, 2021 | In JetBrains TeamCity before 2020.2.3, stored XSS was possible on several pages. |
| CVE-2021-31907 | MEDIUM | 5.3 | 0.9% | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, permission checks for changing TeamCity plugins were implemented improperly. |
| CVE-2021-31904 | MEDIUM | 6.1 | 0.7% | May 11, 2021 | In JetBrains TeamCity before 2020.2.2, XSS was potentially possible on the test history page. |
| CVE-2021-31903 | MEDIUM | 6.1 | 0.8% | May 11, 2021 | In JetBrains YouTrack before 2021.1.9819, a pull request's title was sanitized insufficiently, leading to XSS. |
| CVE-2021-31900 | MEDIUM | 5.3 | 0.7% | May 11, 2021 | In JetBrains Code With Me bundled to the compatible IDE versions before 2021.1, a client could open a browser on a host. |
| CVE-2021-27733 | MEDIUM | 5.4 | 0.6% | May 11, 2021 | In JetBrains YouTrack before 2020.6.6441, stored XSS was possible via an issue attachment. |
| CVE-2021-32544 | MEDIUM | 5.4 | 0.6% | May 11, 2021 | Special characters of IGT search function in igt+ are not filtered in specific fields, which allow remote authenticated ... |
| CVE-2021-30174 | MEDIUM | 5.4 | 0.6% | May 11, 2021 | RiyaLab CloudISO event item is added, special characters in specific field of time management page are not properly filt... |
| CVE-2021-32489 | MEDIUM | 4.4 | 0.9% | May 10, 2021 | An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not ... |
| CVE-2021-32053 | MEDIUM | 5.3 | 1.6% | May 10, 2021 | JPA Server in HAPI FHIR before 5.4.0 allows a user to deny service (e.g., disable access to the database after the attac... |
| CVE-2021-21430 | MEDIUM | 5.5 | 0.4% | May 10, 2021 | OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configurat... |
| CVE-2021-29022 | MEDIUM | 5.3 | 1.0% | May 10, 2021 | In InvoicePlane 1.5.11, the upload feature discloses the full path of the file upload directory. |
| CVE-2021-29502 | MEDIUM | 6.5 | 0.8% | May 10, 2021 | WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to... |
| CVE-2021-29501 | MEDIUM | 6.5 | 0.9% | May 10, 2021 | Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users t... |
| CVE-2021-20577 | MEDIUM | 6.1 | 0.6% | May 10, 2021 | IBM Cloud Pak for Security (CP4S) 1.5.0.0 and 1.5.0.1 is vulnerable to cross-site scripting. This vulnerability allows u... |
| CVE-2021-20559 | MEDIUM | 5.4 | 0.5% | May 10, 2021 | IBM Control Desk 7.6.1.2 and 7.6.1.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arb... |
| CVE-2021-23016 | MEDIUM | 5.3 | 0.8% | May 10, 2021 | On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 1... |
| CVE-2021-32056 | MEDIUM | 4.3 | 1.7% | May 10, 2021 | Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access r... |
| CVE-2021-25645 | MEDIUM | 4.4 | 0.2% | May 10, 2021 | An issue was discovered in Couchbase Server before 6.0.5, 6.1.x through 6.5.x before 6.5.2, and 6.6.x before 6.6.1. An i... |
| CVE-2021-20717 | MEDIUM | 6.1 | 2.3% | May 10, 2021 | Cross-site scripting vulnerability in EC-CUBE 4.0.0 to 4.0.5 allows a remote attacker to inject a specially crafted scri... |
| CVE-2021-3003 | MEDIUM | 5.3 | 0.8% | May 10, 2021 | Agenzia delle Entrate Desktop Telematico 1.0.0 contacts the jws.agenziaentrate.it server over cleartext HTTP, which allo... |
| CVE-2021-31471 | MEDIUM | 5.5 | 2.1% | May 7, 2021 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Reader 1... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now