2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27736 | MEDIUM | 6.5 | 1.3% | Apr 22, 2021 | FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFro... |
| CVE-2021-31554 | MEDIUM | 5.4 | 0.5% | Apr 22, 2021 | An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It improperly handled account blocks ... |
| CVE-2021-31553 | MEDIUM | 6.5 | 1.4% | Apr 22, 2021 | An issue was discovered in the CheckUser extension for MediaWiki through 1.35.2. MediaWiki usernames with trailing white... |
| CVE-2021-31552 | MEDIUM | 5.4 | 0.6% | Apr 22, 2021 | An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly executed certain rules... |
| CVE-2021-31551 | MEDIUM | 6.1 | 0.9% | Apr 22, 2021 | An issue was discovered in the PageForms extension for MediaWiki through 1.35.2. Crafted payloads for Token-related quer... |
| CVE-2021-31550 | MEDIUM | 5.4 | 0.4% | Apr 22, 2021 | An issue was discovered in the CommentBox extension for MediaWiki through 1.35.2. Via crafted configuration variables, a... |
| CVE-2021-31549 | MEDIUM | 4.3 | 0.8% | Apr 22, 2021 | An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The Special:AbuseFilter/examine form ... |
| CVE-2021-31548 | MEDIUM | 6.5 | 0.7% | Apr 22, 2021 | An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. A MediaWiki user who is partially blo... |
| CVE-2021-31547 | MEDIUM | 4.3 | 0.9% | Apr 22, 2021 | An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. Its AbuseFilterCheckMatch API reveals... |
| CVE-2021-31546 | MEDIUM | 4.3 | 0.7% | Apr 22, 2021 | An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. It incorrectly logged sensitive suppr... |
| CVE-2021-31545 | MEDIUM | 5.3 | 0.8% | Apr 22, 2021 | An issue was discovered in the AbuseFilter extension for MediaWiki through 1.35.2. The page_recent_contributors leaked t... |
| CVE-2021-29467 | MEDIUM | 6.1 | 0.5% | Apr 22, 2021 | Wrongthink is an encrypted peer-to-peer chat program. A user could check their fingerprint into the service and enter a ... |
| CVE-2021-1078 | MEDIUM | 5.5 | 0.2% | Apr 21, 2021 | NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel driver (nvlddmkm.sys... |
| CVE-2021-1077 | MEDIUM | 5.5 | 0.3% | Apr 21, 2021 | NVIDIA GPU Display Driver for Windows and Linux, R450 and R460 driver branch, contains a vulnerability where the softwar... |
| CVE-2021-29456 | MEDIUM | 5.4 | 0.5% | Apr 21, 2021 | Authelia is an open-source authentication and authorization server providing 2-factor authentication and single sign-on ... |
| CVE-2021-28167 | MEDIUM | 6.5 | 1.1% | Apr 21, 2021 | In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to ... |
| CVE-2021-31329 | MEDIUM | 5.4 | 1.7% | Apr 21, 2021 | Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php |
| CVE-2021-31327 | MEDIUM | 5.4 | 1.7% | Apr 21, 2021 | Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field. |
| CVE-2021-21647 | MEDIUM | 4.3 | 1.5% | Apr 21, 2021 | Jenkins CloudBees CD Plugin 1.1.21 and earlier does not perform a permission check in an HTTP endpoint, allowing attacke... |
| CVE-2021-21645 | MEDIUM | 4.3 | 0.9% | Apr 21, 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not perform permission checks in several HTTP endpoints, atta... |
| CVE-2021-21644 | MEDIUM | 5.4 | 1.1% | Apr 21, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Config File Provider Plugin 3.7.0 and earlier allows attack... |
| CVE-2021-21643 | MEDIUM | 6.5 | 1.1% | Apr 21, 2021 | Jenkins Config File Provider Plugin 3.7.0 and earlier does not correctly perform permission checks in several HTTP endpo... |
| CVE-2021-29459 | MEDIUM | 6.1 | 1.1% | Apr 20, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. It is possible ... |
| CVE-2021-21526 | MEDIUM | 6.7 | 0.3% | Apr 20, 2021 | Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmi... |
| CVE-2021-30496 | MEDIUM | 5.7 | 1.2% | Apr 20, 2021 | The Telegram app 7.6.2 for iOS allows remote authenticated users to cause a denial of service (application crash) if the... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now