2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27851 | MEDIUM | 5.5 | 0.3% | Apr 26, 2021 | A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-u... |
| CVE-2021-3494 | MEDIUM | 5.9 | 0.4% | Apr 26, 2021 | A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause ... |
| CVE-2021-28399 | MEDIUM | 5.3 | 1.0% | Apr 26, 2021 | OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password f... |
| CVE-2021-25838 | MEDIUM | 6.1 | 0.6% | Apr 26, 2021 | The Import function in MintHCM RELEASE 3.0.8 allows an attacker to execute a cross-site scripting (XSS) payload in file-... |
| CVE-2021-28079 | MEDIUM | 6.1 | 1.2% | Apr 26, 2021 | Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the E... |
| CVE-2021-31804 | MEDIUM | 5.5 | 0.8% | Apr 26, 2021 | LeoCAD before 21.03 sometimes allows a use-after-free during the opening of a new document. |
| CVE-2021-31803 | MEDIUM | 6.1 | 0.6% | Apr 26, 2021 | cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581). |
| CVE-2021-20712 | MEDIUM | 5.3 | 0.8% | Apr 26, 2021 | Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware V... |
| CVE-2021-20710 | MEDIUM | 6.1 | 0.8% | Apr 26, 2021 | Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an ... |
| CVE-2021-20680 | MEDIUM | 6.1 | 0.8% | Apr 26, 2021 | Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP ... |
| CVE-2021-31712 | MEDIUM | 5.4 | 0.8% | Apr 24, 2021 | react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decora... |
| CVE-2021-31794 | MEDIUM | 6.1 | 0.7% | Apr 24, 2021 | Settings.aspx?view=About in Directum 5.8.2 allows XSS via the HTTP User-Agent header. |
| CVE-2021-31583 | MEDIUM | 5.4 | 1.1% | Apr 23, 2021 | Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stor... |
| CVE-2021-29158 | MEDIUM | 4.9 | 0.8% | Apr 23, 2021 | Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control. |
| CVE-2021-29470 | MEDIUM | 6.5 | 1.6% | Apr 23, 2021 | Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file... |
| CVE-2021-22207 | MEDIUM | 6.5 | 2.0% | Apr 23, 2021 | Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of servic... |
| CVE-2021-31539 | MEDIUM | 5.5 | 0.3% | Apr 23, 2021 | Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.pass... |
| CVE-2021-26909 | MEDIUM | 5.3 | 0.7% | Apr 23, 2021 | Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which... |
| CVE-2021-25382 | MEDIUM | 5.5 | 0.1% | Apr 23, 2021 | An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorize... |
| CVE-2021-2315 | MEDIUM | 5.4 | 1.0% | Apr 22, 2021 | Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported version... |
| CVE-2021-2312 | MEDIUM | 4.4 | 0.3% | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that... |
| CVE-2021-2311 | MEDIUM | 6.5 | 1.0% | Apr 22, 2021 | Vulnerability in the Oracle Hospitality Inventory Management product of Oracle Food and Beverage Applications (component... |
| CVE-2021-2307 | MEDIUM | 6.1 | 1.0% | Apr 22, 2021 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are af... |
| CVE-2021-2306 | MEDIUM | 6 | 0.4% | Apr 22, 2021 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that... |
| CVE-2021-2305 | MEDIUM | 4.9 | 1.2% | Apr 22, 2021 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now