2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29146 | MEDIUM | 5.4 | 0.5% | Apr 29, 2021 | A remote cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6... |
| CVE-2021-29144 | MEDIUM | 6.5 | 1.1% | Apr 29, 2021 | A remote disclosure of sensitive information vulnerability was discovered in Aruba ClearPass Policy Manager version(s) p... |
| CVE-2021-29137 | MEDIUM | 6.1 | 0.8% | Apr 29, 2021 | A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1.... |
| CVE-2021-31879 | MEDIUM | 6.1 | 1.1% | Apr 29, 2021 | GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to... |
| CVE-2021-25214 | MEDIUM | 6.5 | 5.9% | Apr 29, 2021 | In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9... |
| CVE-2021-21391 | MEDIUM | 6.5 | 1.7% | Apr 29, 2021 | CKEditor 5 provides a WYSIWYG editing solution. This CVE affects the following npm packages: ckeditor5-engine, ckeditor5... |
| CVE-2021-2321 | MEDIUM | 6 | 0.6% | Apr 28, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that... |
| CVE-2021-25164 | MEDIUM | 6.5 | 1.3% | Apr 28, 2021 | A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.1... |
| CVE-2021-23364 | MEDIUM | 5.3 | 2.4% | Apr 28, 2021 | The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) dur... |
| CVE-2021-3508 | MEDIUM | 5.5 | 0.8% | Apr 28, 2021 | A flaw was found in PDFResurrect in version 0.22b. There is an infinite loop in get_xref_linear_skipped() in pdf.c via a... |
| CVE-2021-29388 | MEDIUM | 5.4 | 0.5% | Apr 28, 2021 | A stored cross-site scripting (XSS) vulnerability in SourceCodester Budget Management System 1.0 allows users to inject ... |
| CVE-2021-29387 | MEDIUM | 5.4 | 0.8% | Apr 28, 2021 | Multiple stored cross-site scripting (XSS) vulnerabilities in Sourcecodester Equipment Inventory System 1.0 allow remote... |
| CVE-2021-29159 | MEDIUM | 6.1 | 0.7% | Apr 28, 2021 | A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacke... |
| CVE-2021-22330 | MEDIUM | 6.5 | 0.3% | Apr 28, 2021 | There is an out of bounds write vulnerability in Huawei Smartphone HUAWEI P30 versions 9.1.0.131(C00E130R1P21) when proc... |
| CVE-2021-22327 | MEDIUM | 6.5 | 0.5% | Apr 28, 2021 | There is an arbitrary memory write vulnerability in Huawei smart phone when processing file parsing. Due to insufficient... |
| CVE-2021-31866 | MEDIUM | 5.3 | 1.2% | Apr 28, 2021 | Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attacker to learn the values of internal authentication keys by ob... |
| CVE-2021-31865 | MEDIUM | 5.3 | 1.1% | Apr 28, 2021 | Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows users to circumvent the allowed filename extensi... |
| CVE-2021-31864 | MEDIUM | 5.3 | 1.2% | Apr 28, 2021 | Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4.2.1 allows attackers to bypass the add_issue_notes permissi... |
| CVE-2021-31779 | MEDIUM | 6.4 | 0.5% | Apr 28, 2021 | The yoast_seo (aka Yoast SEO) extension before 7.2.1 for TYPO3 allows SSRF via a backend user account. |
| CVE-2021-31778 | MEDIUM | 5.4 | 0.5% | Apr 28, 2021 | The media2click (aka 2 Clicks for External Media) extension 1.x before 1.3.3 for TYPO3 allows XSS by a backend user acco... |
| CVE-2021-31777 | MEDIUM | 4.9 | 1.4% | Apr 28, 2021 | The dce (aka Dynamic Content Element) extension 2.2.0 through 2.6.x before 2.6.2, and 2.7.x before 2.7.1, for TYPO3 allo... |
| CVE-2021-27933 | MEDIUM | 6.1 | 26.6% | Apr 28, 2021 | pfSense 2.5.0 allows XSS via the services_wol_edit.php Description field. |
| CVE-2021-3511 | MEDIUM | 4.3 | 0.5% | Apr 28, 2021 | Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmwar... |
| CVE-2021-29460 | MEDIUM | 5.4 | 3.2% | Apr 27, 2021 | Kirby is an open source CMS. An editor with write access to the Kirby Panel can upload an SVG file that contains harmful... |
| CVE-2021-21365 | MEDIUM | 5.4 | 0.9% | Apr 27, 2021 | Bootstrap Package is a theme for TYPO3. It has been discovered that rendering content in the website frontend is vulnera... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now