2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29453 | MEDIUM | 6.5 | 1.0% | Apr 19, 2021 | matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media... |
| CVE-2021-29434 | MEDIUM | 4.8 | 0.6% | Apr 19, 2021 | Wagtail is a Django content management system. In affected versions of Wagtail, when saving the contents of a rich text ... |
| CVE-2021-27029 | MEDIUM | 5.5 | 0.8% | Apr 19, 2021 | The user may be tricked into opening a malicious FBX file which may exploit a Null Pointer Dereference vulnerability in ... |
| CVE-2021-20989 | MEDIUM | 5.9 | 2.0% | Apr 19, 2021 | Fibaro Home Center 2 and Lite devices with firmware version 4.600 and older initiate SSH connections to the Fibaro cloud... |
| CVE-2021-21070 | MEDIUM | 6.5 | 1.6% | Apr 19, 2021 | Adobe Robohelp version 2020.0.3 (and earlier) is affected by an uncontrolled search path element vulnerability that coul... |
| CVE-2021-29399 | MEDIUM | 6.1 | 0.8% | Apr 19, 2021 | XMB is vulnerable to cross-site scripting (XSS) due to inadequate filtering of BBCode input. This bug affects all versio... |
| CVE-2021-29452 | MEDIUM | 6.5 | 0.8% | Apr 16, 2021 | a12n-server is an npm package which aims to provide a simple authentication system. A new HAL-Form was added to allow ed... |
| CVE-2021-29446 | MEDIUM | 5.9 | 1.2% | Apr 16, 2021 | jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 ... |
| CVE-2021-29445 | MEDIUM | 5.9 | 1.2% | Apr 16, 2021 | jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 ... |
| CVE-2021-29444 | MEDIUM | 5.9 | 1.2% | Apr 16, 2021 | jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 t... |
| CVE-2021-31348 | MEDIUM | 6.5 | 1.1% | Apr 16, 2021 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling ... |
| CVE-2021-31347 | MEDIUM | 6.5 | 1.2% | Apr 16, 2021 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs incorrect memory handling ... |
| CVE-2021-29443 | MEDIUM | 5.9 | 1.2% | Apr 16, 2021 | jose is an npm library providing a number of cryptographic operations. In vulnerable versions AES_CBC_HMAC_SHA2 Algorith... |
| CVE-2021-20491 | MEDIUM | 4.4 | 0.3% | Apr 16, 2021 | IBM Spectrum Protect Server 7.1 and 8.1 is subject to a stack-based buffer overflow caused by improper bounds checking d... |
| CVE-2021-26074 | MEDIUM | 6.5 | 0.7% | Apr 16, 2021 | Broken Authentication in Atlassian Connect Spring Boot (ACSB) from version 1.1.0 before version 2.1.3: Atlassian Connect... |
| CVE-2021-29450 | MEDIUM | 4.3 | 2.3% | Apr 15, 2021 | Wordpress is an open source CMS. One of the blocks in the WordPress editor can be exploited in a way that exposes passwo... |
| CVE-2021-29447 | MEDIUM | 6.5 | 85.7% | Apr 15, 2021 | Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing iss... |
| CVE-2021-29432 | MEDIUM | 5.7 | 0.9% | Apr 15, 2021 | Sydent is a reference matrix identity server. A malicious user could abuse Sydent to send out arbitrary emails from the ... |
| CVE-2021-29431 | MEDIUM | 6.5 | 1.2% | Apr 15, 2021 | Sydent is a reference Matrix identity server. Sydent can be induced to send HTTP GET requests to internal systems, due t... |
| CVE-2021-28055 | MEDIUM | 6.5 | 0.8% | Apr 15, 2021 | An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, whi... |
| CVE-2021-29433 | MEDIUM | 4.3 | 0.9% | Apr 15, 2021 | Sydent is a reference Matrix identity server. In Sydent versions 2.2.0 and prior, sissing input validation of some param... |
| CVE-2021-26582 | MEDIUM | 6.1 | 0.7% | Apr 15, 2021 | A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0... |
| CVE-2021-3243 | MEDIUM | 6.1 | 0.7% | Apr 15, 2021 | Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet ... |
| CVE-2021-31229 | MEDIUM | 6.5 | 1.0% | Apr 15, 2021 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd() performs incorrect memory handli... |
| CVE-2021-30209 | MEDIUM | 6.5 | 0.8% | Apr 15, 2021 | Textpattern V4.8.4 contains an arbitrary file upload vulnerability where a plug-in can be loaded in the background witho... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now