2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-29642 | MEDIUM | 5.3 | 0.9% | Mar 30, 2021 | GistPad before 0.2.7 allows a crafted workspace folder to change the URL for the Gist API, which leads to leakage of Git... |
| CVE-2021-3476 | MEDIUM | 5.3 | 1.8% | Mar 30, 2021 | A flaw was found in OpenEXR's B44 uncompression functionality in versions before 3.0.0-beta. An attacker who is able to ... |
| CVE-2021-3475 | MEDIUM | 5.3 | 1.8% | Mar 30, 2021 | There is a flaw in OpenEXR in versions before 3.0.0-beta. An attacker who can submit a crafted file to be processed by O... |
| CVE-2021-3474 | MEDIUM | 5.3 | 1.8% | Mar 30, 2021 | There's a flaw in OpenEXR in versions before 3.0.0-beta. A crafted input file that is processed by OpenEXR could cause a... |
| CVE-2021-26579 | MEDIUM | 5.5 | 0.2% | Mar 30, 2021 | A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information... |
| CVE-2021-20520 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2021-20518 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2021-20506 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2021-20504 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2021-20503 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2021-20447 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2021-20352 | MEDIUM | 5.4 | 0.5% | Mar 30, 2021 | IBM Jazz Foundation Products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary ... |
| CVE-2021-21398 | MEDIUM | 5.4 | 0.7% | Mar 30, 2021 | PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.7.3, an attacker can in... |
| CVE-2021-21409 | MEDIUM | 5.9 | 4.9% | Mar 30, 2021 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h... |
| CVE-2021-29343 | MEDIUM | 5.4 | 0.8% | Mar 30, 2021 | Ovidentia CMS 6.x contains a SQL injection vulnerability in the "id" parameter of index.php. The "checkbox" property int... |
| CVE-2021-28935 | MEDIUM | 5.4 | 1.6% | Mar 30, 2021 | CMS Made Simple (CMSMS) 2.2.15 allows authenticated XSS via the /admin/addbookmark.php script through the Site Admin > M... |
| CVE-2021-21637 | MEDIUM | 6.5 | 1.0% | Mar 30, 2021 | A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Re... |
| CVE-2021-21636 | MEDIUM | 4.3 | 0.8% | Mar 30, 2021 | A missing permission check in Jenkins Team Foundation Server Plugin 5.157.1 and earlier allows attackers with Overall/Re... |
| CVE-2021-21635 | MEDIUM | 5.4 | 8.8% | Mar 30, 2021 | Jenkins REST List Parameter Plugin 1.3.0 and earlier does not escape a parameter name reference in embedded JavaScript, ... |
| CVE-2021-21634 | MEDIUM | 6.5 | 0.8% | Mar 30, 2021 | Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configurat... |
| CVE-2021-21632 | MEDIUM | 6.5 | 1.1% | Mar 30, 2021 | A missing permission check in Jenkins OWASP Dependency-Track Plugin 3.1.0 and earlier allows attackers with Overall/Read... |
| CVE-2021-21631 | MEDIUM | 4.3 | 0.8% | Mar 30, 2021 | Jenkins Cloud Statistics Plugin 0.26 and earlier does not perform a permission check in an HTTP endpoint, allowing attac... |
| CVE-2021-21630 | MEDIUM | 5.4 | 72.4% | Mar 30, 2021 | Jenkins Extra Columns Plugin 1.22 and earlier does not escape parameter values in the build parameters column, resulting... |
| CVE-2021-21628 | MEDIUM | 5.4 | 81.9% | Mar 30, 2021 | Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, resulting in a st... |
| CVE-2021-29418 | MEDIUM | 5.3 | 1.7% | Mar 30, 2021 | The netmask package before 2.0.1 for Node.js mishandles certain unexpected characters in an IP address string, such as a... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now