2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-22157MEDIUM6.1Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS.
CVE-2021-25692MEDIUM4.6Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway pri...
CVE-2021-28688MEDIUM6.5The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or ...
CVE-2021-30146MEDIUM5.4Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality."
CVE-2021-30140MEDIUM5.4LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrat...
CVE-2021-29136MEDIUM5.5Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that...
CVE-2021-26833MEDIUM5.9Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attac...
CVE-2021-28658MEDIUM5.3In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via up...
CVE-2021-30046MEDIUM6.5VIGRA Computer Vision Library Version-1-11-1 contains a segmentation fault vulnerability in the impex.hxx read_image_ban...
CVE-2021-30161MEDIUM5.5An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection...
CVE-2021-30158MEDIUM5.3An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to...
CVE-2021-30157MEDIUM6.1An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special page...
CVE-2021-30154MEDIUM6.1An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all th...
CVE-2021-30151MEDIUM6.1Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explore...
CVE-2021-30150MEDIUM6.1Composr 10.0.36 allows XSS in an XML script.
CVE-2021-30144MEDIUM4.3The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing infor...
CVE-2021-28209MEDIUM4.9The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specif...
CVE-2021-28208MEDIUM4.9The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific ...
CVE-2021-28207MEDIUM4.9The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific p...
CVE-2021-28206MEDIUM4.9The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specif...
CVE-2021-28205MEDIUM4.9The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the sp...
CVE-2021-28202MEDIUM4.9The Service configuration-2 function in ASUS BMC’s firmware Web management page does not verify the string length entere...
CVE-2021-28201MEDIUM4.9The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entere...
CVE-2021-28200MEDIUM4.9The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered...
CVE-2021-28199MEDIUM4.9The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify th...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now