2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-29642MEDIUM5.3GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of Git...
CVE-2021-3476MEDIUM5.3A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to ...
CVE-2021-3475MEDIUM5.3There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by O...
CVE-2021-3474MEDIUM5.3There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a...
CVE-2021-26579MEDIUM5.5A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information...
CVE-2021-20520MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2021-20518MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2021-20506MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2021-20504MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2021-20503MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2021-20447MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2021-20352MEDIUM5.4IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ...
CVE-2021-21398MEDIUM5.4PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can in...
CVE-2021-21409MEDIUM5.9Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h...
CVE-2021-29343MEDIUM5.4Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property int...
CVE-2021-28935MEDIUM5.4CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > M...
CVE-2021-21637MEDIUM6.5A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Re...
CVE-2021-21636MEDIUM4.3A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Re...
CVE-2021-21635MEDIUM5.4Jenkins REST List Parameter Plugin 1.3.0 and earlier does not escape a parameter name reference in embedded JavaScript, ...
CVE-2021-21634MEDIUM6.5Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configurat...
CVE-2021-21632MEDIUM6.5A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read...
CVE-2021-21631MEDIUM4.3Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attac...
CVE-2021-21630MEDIUM5.4Jenkins Extra Columns Plugin 1.22 and earlier does not escape parameter values in the build parameters column, resulting...
CVE-2021-21628MEDIUM5.4Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, resulting in a st...
CVE-2021-29418MEDIUM5.3The netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as a...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now