2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29453MEDIUM6.5matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media...
CVE-2021-29434MEDIUM4.8Wagtail is a Django content management system. In affected versions of Wagtail, when saving the contents of a rich text ...
CVE-2021-27029MEDIUM5.5The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in ...
CVE-2021-20989MEDIUM5.9Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud...
CVE-2021-21070MEDIUM6.5Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that coul...
CVE-2021-29399MEDIUM6.1XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versio...
CVE-2021-29452MEDIUM6.5a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow ed...
CVE-2021-29446MEDIUM5.9jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 ...
CVE-2021-29445MEDIUM5.9jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 ...
CVE-2021-29444MEDIUM5.9jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 t...
CVE-2021-31348MEDIUM6.5An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling ...
CVE-2021-31347MEDIUM6.5An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling ...
CVE-2021-29443MEDIUM5.9jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorith...
CVE-2021-20491MEDIUM4.4IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking d...
CVE-2021-26074MEDIUM6.5Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect...
CVE-2021-29450MEDIUM4.3Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes passwo...
CVE-2021-29447MEDIUM6.5Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing iss...
CVE-2021-29432MEDIUM5.7Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the ...
CVE-2021-29431MEDIUM6.5Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due t...
CVE-2021-28055MEDIUM6.5An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, whi...
CVE-2021-29433MEDIUM4.3Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some param...
CVE-2021-26582MEDIUM6.1A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0...
CVE-2021-3243MEDIUM6.1Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet ...
CVE-2021-31229MEDIUM6.5An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handli...
CVE-2021-30209MEDIUM6.5Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background witho...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now