2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-30003MEDIUM4.8An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface vi...
CVE-2021-30002MEDIUM6.2An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v...
CVE-2021-23925MEDIUM6.1An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entr...
CVE-2021-23922MEDIUM5.4An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vu...
CVE-2021-21421MEDIUM6.5node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client err...
CVE-2021-28047MEDIUM5.4Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote a...
CVE-2021-28970MEDIUM6.5eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL ...
CVE-2021-28969MEDIUM6.5eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the ...
CVE-2021-27653MEDIUM4.9Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data expos...
CVE-2021-26718MEDIUM5.5KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus p...
CVE-2021-26581MEDIUM6.5A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be r...
CVE-2021-26580MEDIUM6.1A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely ex...
CVE-2021-26072MEDIUM4.3The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers...
CVE-2021-3447MEDIUM5.5A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged...
CVE-2021-22876MEDIUM5.3curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Acto...
CVE-2021-20291MEDIUM6.5A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image ...
CVE-2021-28164MEDIUM5.3In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contai...
CVE-2021-22177MEDIUM4.3Potential DoS was identified in gitlab-shell in GitLab CE/EE version 12.6.0 or above, which allows an attacker to spike ...
CVE-2021-3393MEDIUM4.3An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UP...
CVE-2021-28546MEDIUM6.5Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and e...
CVE-2021-20296MEDIUM5.3A flaw was found in OpenEXR in versions before 3.0.0-beta. A crafted input file supplied by an attacker, that is process...
CVE-2021-20234MEDIUM6.5An uncontrolled resource consumption (memory leak) flaw was found in the ZeroMQ client in versions before 4.3.3 in src/p...
CVE-2021-29251MEDIUM6.5BTCPay Server before 1.0.7.1 mishandles the policy setting in which users can register (in Server Settings > Policies). ...
CVE-2021-29349MEDIUM6.5Mahara 20.10 is affected by Cross Site Request Forgery (CSRF) that allows a remote attacker to remove inbox-mail on the ...
CVE-2021-27349MEDIUM6.1Advanced Order Export before 3.1.8 for WooCommerce allows XSS, a different vulnerability than CVE-2020-11727.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now