2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-27220MEDIUM5.3An issue was discovered in PRTG Network Monitor before 21.1.66.1623. By invoking the screenshot functionality with prepa...
CVE-2021-29663MEDIUM4.8CourseMS (aka Course Registration Management System) 2.1 is affected by cross-site scripting (XSS). When an attacker wit...
CVE-2021-23007MEDIUM5.3On BIG-IP versions 14.1.4 and 16.0.1.1, when the Traffic Management Microkernel (TMM) process handles certain undisclose...
CVE-2021-23006MEDIUM6.1On all 7.x and 6.x versions (fixed in 8.0.0), undisclosed BIG-IQ pages have a reflected cross-site scripting vulnerabili...
CVE-2021-23002MEDIUM4.5When using BIG-IP APM 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, or a...
CVE-2021-23001MEDIUM4.3On versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x before ...
CVE-2021-22998MEDIUM5.3On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x ...
CVE-2021-22994MEDIUM6.1On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, 12.1.x ...
CVE-2021-21983MEDIUM6.5Arbitrary file write vulnerability in vRealize Operations Manager API (CVE-2021-21983) prior to 8.4 may allow an authent...
CVE-2021-21418MEDIUM5.4ps_emailsubscription is a newsletter subscription module for the PrestaShop platform. An employee can inject javascript ...
CVE-2021-3479MEDIUM5.5There's a flaw in OpenEXR's Scanline API functionality in versions before 3.0.0-beta. An attacker who is able to submit ...
CVE-2021-3478MEDIUM5.5There's a flaw in OpenEXR's scanline input file functionality in versions before 3.0.0-beta. An attacker able to submit ...
CVE-2021-3477MEDIUM5.5There's a flaw in OpenEXR's deep tile sample size calculations in versions before 3.0.0-beta. An attacker who is able to...
CVE-2021-3470MEDIUM5.3A heap overflow issue was found in Redis in versions before 5.0.10, before 6.0.9 and before 6.2.0 when using a heap allo...
CVE-2021-23986MEDIUM6.5A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a c...
CVE-2021-23985MEDIUM6.5If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the D...
CVE-2021-23984MEDIUM6.5A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address...
CVE-2021-23983MEDIUM6.5By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applie...
CVE-2021-23982MEDIUM6.5Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network'...
CVE-2021-28657MEDIUM5.5A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apac...
CVE-2021-29650MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial o...
CVE-2021-29649MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak,...
CVE-2021-29648MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_i...
CVE-2021-29647MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain s...
CVE-2021-29646MEDIUM5.5An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly va...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now