2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27673 | MEDIUM | 4.8 | 1.1% | Apr 15, 2021 | Cross Site Scripting (XSS) in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remot... |
| CVE-2021-27672 | MEDIUM | 4.9 | 1.3% | Apr 15, 2021 | SQL Injection in the "admin_boxes.ajax.php" component of Tribal Systems Zenario CMS v8.8.52729 allows remote attackers t... |
| CVE-2021-21096 | MEDIUM | 5.5 | 0.7% | Apr 15, 2021 | Adobe Bridge versions 10.1.1 (and earlier) and 11.0.1 (and earlier) are affected by an Improper Authorization vulnerabil... |
| CVE-2021-21087 | MEDIUM | 5.4 | 37.1% | Apr 15, 2021 | Adobe Coldfusion versions 2016 (update 16 and earlier), 2018 (update 10 and earlier) and 2021.0.0.323925 are affected by... |
| CVE-2021-0488 | MEDIUM | 6.7 | 0.1% | Apr 15, 2021 | In pb_write of pb_encode.c, there is a possible out of bounds write due to a missing bounds check. This could lead to lo... |
| CVE-2021-27545 | MEDIUM | 6.5 | 2.0% | Apr 15, 2021 | SQL Injection in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allows remote atta... |
| CVE-2021-27544 | MEDIUM | 4.8 | 1.1% | Apr 15, 2021 | Cross Site Scripting (XSS) in the "add-services.php" component of PHPGurukul Beauty Parlour Management System v1.0 allow... |
| CVE-2021-27129 | MEDIUM | 5.4 | 0.6% | Apr 15, 2021 | CASAP Automated Enrollment System version 1.0 contains a cross-site scripting (XSS) vulnerability through the Students >... |
| CVE-2021-23886 | MEDIUM | 5.5 | 0.2% | Apr 15, 2021 | Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a loc... |
| CVE-2021-23884 | MEDIUM | 4.3 | 0.2% | Apr 15, 2021 | Cleartext Transmission of Sensitive Information vulnerability in the ePO Extension of McAfee Content Security Reporter (... |
| CVE-2021-30479 | MEDIUM | 5.3 | 0.9% | Apr 15, 2021 | An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the all_public_streams API feature re... |
| CVE-2021-30478 | MEDIUM | 4.3 | 0.6% | Apr 15, 2021 | An issue was discovered in Zulip Server before 3.4. A bug in the implementation of the can_forge_sender permission (prev... |
| CVE-2021-30477 | MEDIUM | 4.3 | 0.7% | Apr 15, 2021 | An issue was discovered in Zulip Server before 3.4. A bug in the implementation of replies to messages sent by outgoing ... |
| CVE-2021-26075 | MEDIUM | 4.3 | 1.6% | Apr 15, 2021 | The Jira importers plugin AttachTemporaryFile rest resource in Jira Server and Data Center before version 8.5.12, from v... |
| CVE-2021-27180 | MEDIUM | 6.1 | 0.9% | Apr 14, 2021 | An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploit... |
| CVE-2021-28048 | MEDIUM | 6.5 | 0.6% | Apr 14, 2021 | An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows ... |
| CVE-2021-26031 | MEDIUM | 5.3 | 1.2% | Apr 14, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate filters on module layout settings could lead to an L... |
| CVE-2021-26030 | MEDIUM | 6.1 | 82.4% | Apr 14, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.25. Inadequate escaping allowed XSS attacks using the logo paramete... |
| CVE-2021-28856 | MEDIUM | 5.5 | 0.9% | Apr 14, 2021 | In Deark before v1.5.8, a specially crafted input file can cause a division by zero in (src/fmtutil.c) because of the va... |
| CVE-2021-28855 | MEDIUM | 5.5 | 0.9% | Apr 14, 2021 | In Deark before 1.5.8, a specially crafted input file can cause a NULL pointer dereference in the dbuf_write function (s... |
| CVE-2021-28060 | MEDIUM | 5.3 | 1.4% | Apr 14, 2021 | A Server-Side Request Forgery (SSRF) vulnerability in Group Office 6.4.196 allows a remote attacker to forge GET request... |
| CVE-2021-27250 | MEDIUM | 6.5 | 66.0% | Apr 14, 2021 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Li... |
| CVE-2021-27247 | MEDIUM | 6.5 | 6.4% | Apr 14, 2021 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tencent WeChat... |
| CVE-2021-30494 | MEDIUM | 5.5 | 0.5% | Apr 14, 2021 | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries... |
| CVE-2021-30493 | MEDIUM | 5.5 | 0.5% | Apr 14, 2021 | Multiple system services installed alongside the Razer Synapse 3 software suite perform privileged operations on entries... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now