2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22157 | MEDIUM | 6.1 | 1.9% | Apr 6, 2021 | Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS. |
| CVE-2021-25692 | MEDIUM | 4.6 | 0.2% | Apr 6, 2021 | Sensitive smart card data is logged in default INFO logs by Teradici's PCoIP Connection Manager and Security Gateway pri... |
| CVE-2021-28688 | MEDIUM | 6.5 | 0.3% | Apr 6, 2021 | The fix for XSA-365 includes initialization of pointers such that subsequent cleanup code wouldn't use uninitialized or ... |
| CVE-2021-30146 | MEDIUM | 5.4 | 0.9% | Apr 6, 2021 | Seafile 7.0.5 (2019) allows Persistent XSS via the "share of library functionality." |
| CVE-2021-30140 | MEDIUM | 5.4 | 1.4% | Apr 6, 2021 | LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrat... |
| CVE-2021-29136 | MEDIUM | 5.5 | 0.3% | Apr 6, 2021 | Open Container Initiative umoci before 0.4.7 allows attackers to overwrite arbitrary host paths via a crafted image that... |
| CVE-2021-26833 | MEDIUM | 5.9 | 1.0% | Apr 6, 2021 | Cleartext Storage in a File or on Disk in TimelyBills <= 1.7.0 for iOS and versions <= 1.21.115 for Android allows attac... |
| CVE-2021-28658 | MEDIUM | 5.3 | 3.9% | Apr 6, 2021 | In Django 2.2 before 2.2.20, 3.0 before 3.0.14, and 3.1 before 3.1.8, MultiPartParser allowed directory traversal via up... |
| CVE-2021-30046 | MEDIUM | 6.5 | 1.0% | Apr 6, 2021 | VIGRA Computer Vision Library Version-1-11-1 contains a segmentation fault vulnerability in the impex.hxx read_image_ban... |
| CVE-2021-30161 | MEDIUM | 5.5 | 0.1% | Apr 6, 2021 | An issue was discovered on LG mobile devices with Android OS 11 software. Attackers can bypass the lockscreen protection... |
| CVE-2021-30158 | MEDIUM | 5.3 | 1.7% | Apr 6, 2021 | An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to... |
| CVE-2021-30157 | MEDIUM | 6.1 | 1.4% | Apr 6, 2021 | An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special page... |
| CVE-2021-30154 | MEDIUM | 6.1 | 1.3% | Apr 6, 2021 | An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all th... |
| CVE-2021-30151 | MEDIUM | 6.1 | 4.2% | Apr 6, 2021 | Sidekiq through 5.1.3 and 6.x through 6.2.0 allows XSS via the queue name of the live-poll feature when Internet Explore... |
| CVE-2021-30150 | MEDIUM | 6.1 | 2.8% | Apr 6, 2021 | Composr 10.0.36 allows XSS in an XML script. |
| CVE-2021-30144 | MEDIUM | 4.3 | 0.8% | Apr 6, 2021 | The Dashboard plugin through 1.0.2 for GLPI allows remote low-privileged users to bypass access control on viewing infor... |
| CVE-2021-28209 | MEDIUM | 4.9 | 1.9% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Delete video file function) does not filter the specif... |
| CVE-2021-28208 | MEDIUM | 4.9 | 1.9% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Get video file function) does not filter the specific ... |
| CVE-2021-28207 | MEDIUM | 4.9 | 1.9% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Get Help file function) does not filter the specific p... |
| CVE-2021-28206 | MEDIUM | 4.9 | 1.9% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Record video file function) does not filter the specif... |
| CVE-2021-28205 | MEDIUM | 4.9 | 1.9% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Delete SOL video file function) does not filter the sp... |
| CVE-2021-28202 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The Service configuration-2 function in ASUS BMC’s firmware Web management page does not verify the string length entere... |
| CVE-2021-28201 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entere... |
| CVE-2021-28200 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The CD media configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered... |
| CVE-2021-28199 | MEDIUM | 4.9 | 1.8% | Apr 6, 2021 | The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not verify th... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now