2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-27736MEDIUM6.5FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFro...
CVE-2021-31554MEDIUM5.4An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks ...
CVE-2021-31553MEDIUM6.5An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing white...
CVE-2021-31552MEDIUM5.4An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules...
CVE-2021-31551MEDIUM6.1An issue was discovered in the PageForms extension for MediaWiki through 1.35.2. Crafted payloads for Token-related quer...
CVE-2021-31550MEDIUM5.4An issue was discovered in the CommentBox extension for MediaWiki through 1.35.2. Via crafted configuration variables, a...
CVE-2021-31549MEDIUM4.3An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The Special:AbuseFilter/examine form ...
CVE-2021-31548MEDIUM6.5An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. A MediaWiki user who is partially blo...
CVE-2021-31547MEDIUM4.3An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. Its AbuseFilterCheckMatch API reveals...
CVE-2021-31546MEDIUM4.3An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppr...
CVE-2021-31545MEDIUM5.3An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked t...
CVE-2021-29467MEDIUM6.1Wrongthink is an encrypted peer-to-peer chat program. A user could check their fingerprint into the service and enter a ...
CVE-2021-1078MEDIUM5.5NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel driver (nvlddmkm.sys...
CVE-2021-1077MEDIUM5.5NVIDIA GPU Display Driver for Windows and Linux, R450 and R460 driver branch, contains a vulnerability where the softwar...
CVE-2021-29456MEDIUM5.4Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on ...
CVE-2021-28167MEDIUM6.5In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to ...
CVE-2021-31329MEDIUM5.4Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
CVE-2021-31327MEDIUM5.4Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
CVE-2021-21647MEDIUM4.3Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attacke...
CVE-2021-21645MEDIUM4.3Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, atta...
CVE-2021-21644MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attack...
CVE-2021-21643MEDIUM6.5Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpo...
CVE-2021-29459MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible ...
CVE-2021-21526MEDIUM6.7Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmi...
CVE-2021-30496MEDIUM5.7The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now