2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29146MEDIUM5.4A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6...
CVE-2021-29144MEDIUM6.5A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) p...
CVE-2021-29137MEDIUM6.1A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1....
CVE-2021-31879MEDIUM6.1GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to...
CVE-2021-25214MEDIUM6.5In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9...
CVE-2021-21391MEDIUM6.5CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5...
CVE-2021-2321MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that...
CVE-2021-25164MEDIUM6.5A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.1...
CVE-2021-23364MEDIUM5.3The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) dur...
CVE-2021-3508MEDIUM5.5A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a...
CVE-2021-29388MEDIUM5.4A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject ...
CVE-2021-29387MEDIUM5.4Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote...
CVE-2021-29159MEDIUM6.1A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacke...
CVE-2021-22330MEDIUM6.5There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when proc...
CVE-2021-22327MEDIUM6.5There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient...
CVE-2021-31866MEDIUM5.3Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by ob...
CVE-2021-31865MEDIUM5.3Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensi...
CVE-2021-31864MEDIUM5.3Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permissi...
CVE-2021-31779MEDIUM6.4The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account.
CVE-2021-31778MEDIUM5.4The media2click (aka 2 Clicks for External Media) extension 1.x before 1.3.3 for TYPO3 allows XSS by a backend user acco...
CVE-2021-31777MEDIUM4.9The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allo...
CVE-2021-27933MEDIUM6.1pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field.
CVE-2021-3511MEDIUM4.3Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmwar...
CVE-2021-29460MEDIUM5.4Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful...
CVE-2021-21365MEDIUM5.4Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnera...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now