2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30003 | MEDIUM | 4.8 | 0.6% | Apr 2, 2021 | An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface vi... |
| CVE-2021-30002 | MEDIUM | 6.2 | 0.4% | Apr 2, 2021 | An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v... |
| CVE-2021-23925 | MEDIUM | 6.1 | 0.6% | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entr... |
| CVE-2021-23922 | MEDIUM | 5.4 | 1.1% | Apr 1, 2021 | An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vu... |
| CVE-2021-21421 | MEDIUM | 6.5 | 1.1% | Apr 1, 2021 | node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client err... |
| CVE-2021-28047 | MEDIUM | 5.4 | 1.1% | Apr 1, 2021 | Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote a... |
| CVE-2021-28970 | MEDIUM | 6.5 | 1.3% | Apr 1, 2021 | eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL ... |
| CVE-2021-28969 | MEDIUM | 6.5 | 1.3% | Apr 1, 2021 | eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the ... |
| CVE-2021-27653 | MEDIUM | 4.9 | 1.1% | Apr 1, 2021 | Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data expos... |
| CVE-2021-26718 | MEDIUM | 5.5 | 0.2% | Apr 1, 2021 | KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus p... |
| CVE-2021-26581 | MEDIUM | 6.5 | 0.8% | Apr 1, 2021 | A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be r... |
| CVE-2021-26580 | MEDIUM | 6.1 | 0.6% | Apr 1, 2021 | A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely ex... |
| CVE-2021-26072 | MEDIUM | 4.3 | 38.8% | Apr 1, 2021 | The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers... |
| CVE-2021-3447 | MEDIUM | 5.5 | 0.3% | Apr 1, 2021 | A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged... |
| CVE-2021-22876 | MEDIUM | 5.3 | 5.3% | Apr 1, 2021 | curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Acto... |
| CVE-2021-20291 | MEDIUM | 6.5 | 1.6% | Apr 1, 2021 | A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image ... |
| CVE-2021-28164 | MEDIUM | 5.3 | 82.4% | Apr 1, 2021 | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai... |
| CVE-2021-22177 | MEDIUM | 4.3 | 1.2% | Apr 1, 2021 | Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike ... |
| CVE-2021-3393 | MEDIUM | 4.3 | 1.2% | Apr 1, 2021 | An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UP... |
| CVE-2021-28546 | MEDIUM | 6.5 | 1.4% | Apr 1, 2021 | Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e... |
| CVE-2021-20296 | MEDIUM | 5.3 | 1.7% | Apr 1, 2021 | A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is process... |
| CVE-2021-20234 | MEDIUM | 6.5 | 1.1% | Apr 1, 2021 | An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/p... |
| CVE-2021-29251 | MEDIUM | 6.5 | 0.8% | Apr 1, 2021 | BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). ... |
| CVE-2021-29349 | MEDIUM | 6.5 | 1.5% | Mar 31, 2021 | Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the ... |
| CVE-2021-27349 | MEDIUM | 6.1 | 0.8% | Mar 31, 2021 | Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now