2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-30458MEDIUM6.1An issue was discovered in Wikimedia Parsoid before 0.11.1 and 0.12.x before 0.12.2. An attacker can send crafted wikite...
CVE-2021-30159MEDIUM4.3An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended r...
CVE-2021-30156MEDIUM4.3An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Special:Contributions can l...
CVE-2021-30155MEDIUM4.3An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not...
CVE-2021-30152MEDIUM4.3An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki AP...
CVE-2021-3482MEDIUM6.5A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size pro...
CVE-2021-3448MEDIUM4A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interf...
CVE-2021-3413MEDIUM6.3A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was id...
CVE-2021-22513MEDIUM6.5Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerabili...
CVE-2021-22512MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The...
CVE-2021-22511MEDIUM6.5Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The v...
CVE-2021-22510MEDIUM6.1Reflected XSS vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affec...
CVE-2021-22312MEDIUM6.5There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerab...
CVE-2021-22115MEDIUM6.5Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config...
CVE-2021-27945MEDIUM6.1The Squirro Insights Engine was affected by a Reflected Cross-Site Scripting (XSS) vulnerability affecting versions 2.0....
CVE-2021-28924MEDIUM6.1Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.
CVE-2021-20480MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a spe...
CVE-2021-30114MEDIUM6.5Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create ...
CVE-2021-30113MEDIUM6.1A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attac...
CVE-2021-30112MEDIUM6.5Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create ...
CVE-2021-30111MEDIUM5.4A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An ...
CVE-2021-3012MEDIUM5.4A cross-site scripting (XSS) vulnerability in the Document Link of documents in ESRI Enterprise before 10.9 allows remot...
CVE-2021-28686MEDIUM5.5AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buf...
CVE-2021-28174MEDIUM6.5Mitake smart stock selection system contains a broken authentication vulnerability. By manipulating the parameters in th...
CVE-2021-1475MEDIUM4.1Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could all...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now