2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-27851MEDIUM5.5A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-u...
CVE-2021-3494MEDIUM5.9A smart proxy that provides a restful API to various sub-systems of the Foreman is affected by the flaw which can cause ...
CVE-2021-28399MEDIUM5.3OrangeHRM 4.7 allows an unauthenticated user to enumerate the valid username and email address via the forgot password f...
CVE-2021-25838MEDIUM6.1The Import function in MintHCM RELEASE 3.0.8 allows an attacker to execute a cross-site scripting (XSS) payload in file-...
CVE-2021-28079MEDIUM6.1Jamovi <=1.6.18 is affected by a cross-site scripting (XSS) vulnerability. The column-name is vulnerable to XSS in the E...
CVE-2021-31804MEDIUM5.5LeoCAD before 21.03 sometimes allows a use-after-free during the opening of a new document.
CVE-2021-31803MEDIUM6.1cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
CVE-2021-20712MEDIUM5.3Improper access control vulnerability in NEC Aterm WG2600HS firmware Ver1.5.1 and earlier, and Aterm WX3000HP firmware V...
CVE-2021-20710MEDIUM6.1Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an ...
CVE-2021-20680MEDIUM6.1Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP ...
CVE-2021-31712MEDIUM5.4react-draft-wysiwyg (aka React Draft Wysiwyg) before 1.14.6 allows a javascript: URi in a Link Target of the link decora...
CVE-2021-31794MEDIUM6.1Settings.aspx?view=About in Directum 5.8.2 allows XSS via the HTTP User-Agent header.
CVE-2021-31583MEDIUM5.4Sipwise C5 NGCP WWW Admin version 3.6.7 up to and including platform version NGCP CE 3.0 has multiple authenticated stor...
CVE-2021-29158MEDIUM4.9Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
CVE-2021-29470MEDIUM6.5Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image file...
CVE-2021-22207MEDIUM6.5Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of servic...
CVE-2021-31539MEDIUM5.5Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.pass...
CVE-2021-26909MEDIUM5.3Automox Agent prior to version 31 uses an insufficiently protected S3 bucket endpoint for storing sensitive files, which...
CVE-2021-25382MEDIUM5.5An improper authorization of using debugging command in Secure Folder prior to SMR Oct-2020 Release 1 allows unauthorize...
CVE-2021-2315MEDIUM5.4Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported version...
CVE-2021-2312MEDIUM4.4Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that...
CVE-2021-2311MEDIUM6.5Vulnerability in the Oracle Hospitality Inventory Management product of Oracle Food and Beverage Applications (component...
CVE-2021-2307MEDIUM6.1Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are af...
CVE-2021-2306MEDIUM6Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that...
CVE-2021-2305MEDIUM4.9Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now