2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20519 | MEDIUM | 5.4 | 0.6% | Apr 12, 2021 | IBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary... |
| CVE-2021-24024 | MEDIUM | 6.5 | 0.9% | Apr 12, 2021 | A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and ... |
| CVE-2021-22190 | MEDIUM | 6.5 | 1.3% | Apr 12, 2021 | A path traversal vulnerability via the GitLab Workhorse in all versions of GitLab could result in the leakage of a JWT t... |
| CVE-2021-25926 | MEDIUM | 6.1 | 0.8% | Apr 12, 2021 | In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user inp... |
| CVE-2021-25925 | MEDIUM | 5.4 | 0.7% | Apr 12, 2021 | in SiCKRAGE, versions 4.2.0 to 10.0.11.dev1 are vulnerable to Stored Cross-Site-Scripting (XSS) due to user input not be... |
| CVE-2021-24231 | MEDIUM | 6.5 | 0.6% | Apr 12, 2021 | The Jetpack Scan team identified a Cross-Site Request Forgery vulnerability in the Patreon WordPress plugin before 1.7.0... |
| CVE-2021-24225 | MEDIUM | 5.4 | 0.7% | Apr 12, 2021 | The Advanced Booking Calendar WordPress plugin before 1.6.7 did not sanitise the calId GET parameter in the "Seasons & C... |
| CVE-2021-24219 | MEDIUM | 5.3 | 2.1% | Apr 12, 2021 | The Thrive Optimize WordPress plugin before 1.4.13.3, Thrive Comments WordPress plugin before 1.4.15.3, Thrive Headline ... |
| CVE-2021-24213 | MEDIUM | 6.1 | 1.4% | Apr 12, 2021 | The GiveWP – Donation Plugin and Fundraising Platform WordPress plugin before 2.10.0 was affected by a reflected Cross-S... |
| CVE-2021-24200 | MEDIUM | 6.5 | 1.3% | Apr 12, 2021 | The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user... |
| CVE-2021-24199 | MEDIUM | 6.5 | 1.3% | Apr 12, 2021 | The wpDataTables – Tables & Table Charts premium WordPress plugin before 3.4.2 allows a low privilege authenticated user... |
| CVE-2021-23368 | MEDIUM | 5.3 | 3.5% | Apr 12, 2021 | The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expression Denial of Service (ReDoS) during s... |
| CVE-2021-28876 | MEDIUM | 5.3 | 1.6% | Apr 11, 2021 | In the standard library in Rust before 1.52.0, the Zip implementation has a panic safety issue. It calls __iterator_get_... |
| CVE-2021-30485 | MEDIUM | 6.5 | 1.2% | Apr 11, 2021 | An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_internal_dtd(), while parsing a crafted XML fil... |
| CVE-2021-25378 | MEDIUM | 5.3 | 1.0% | Apr 9, 2021 | Improper access control of certain port in SmartThings prior to version 1.7.63.6 allows remote temporary denial of servi... |
| CVE-2021-25376 | MEDIUM | 5.3 | 0.8% | Apr 9, 2021 | An improper synchronization logic in Samsung Email prior to version 6.1.41.0 can leak messages in certain mailbox in pla... |
| CVE-2021-25375 | MEDIUM | 6.5 | 1.2% | Apr 9, 2021 | Using predictable index for attachments in Samsung Email prior to version 6.1.41.0 allows remote attackers to get attach... |
| CVE-2021-25363 | MEDIUM | 6.1 | 0.1% | Apr 9, 2021 | An improper access control in ActivityManagerService prior to SMR APR-2021 Release 1 allows untrusted applications to ac... |
| CVE-2021-25362 | MEDIUM | 6.1 | 0.1% | Apr 9, 2021 | An improper permission management in CertInstaller prior to SMR APR-2021 Release 1 allows untrusted applications to dele... |
| CVE-2021-25357 | MEDIUM | 5.5 | 0.1% | Apr 9, 2021 | A pendingIntent hijacking vulnerability in Create Movie prior to SMR APR-2021 Release 1 in Android O(8.x) and P(9.0), 3.... |
| CVE-2021-21728 | MEDIUM | 5.3 | 1.0% | Apr 9, 2021 | A ZTE product has a configuration error vulnerability. Because a certain port is open by default, an attacker can consum... |
| CVE-2021-21432 | MEDIUM | 6.5 | 1.0% | Apr 9, 2021 | Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. An authentication... |
| CVE-2021-20080 | MEDIUM | 6.1 | 93.1% | Apr 9, 2021 | Insufficient output sanitization in ManageEngine ServiceDesk Plus before version 11200 and ManageEngine AssetExplorer be... |
| CVE-2021-25327 | MEDIUM | 6.5 | 0.9% | Apr 9, 2021 | Skyworth Digital Technology RN510 V.3.1.0.4 contains a cross-site request forgery (CSRF) vulnerability in /cgi-bin/net-r... |
| CVE-2021-25326 | MEDIUM | 5.4 | 1.5% | Apr 9, 2021 | Skyworth Digital Technology RN510 V.3.1.0.4 is affected by an incorrect access control vulnerability in/cgi-bin/test_ver... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now