2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-26069MEDIUM5.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary ...
CVE-2021-28957MEDIUM6.1An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_o...
CVE-2021-28951MEDIUM5.5An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of se...
CVE-2021-28950MEDIUM5.5An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retr...
CVE-2021-27520MEDIUM6.1A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "...
CVE-2021-27519MEDIUM6.1A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "...
CVE-2021-20077MEDIUM6.7Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local h...
CVE-2021-25278MEDIUM4.8FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template ...
CVE-2021-25277MEDIUM6.1FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component.
CVE-2021-27906MEDIUM5.5A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFB...
CVE-2021-27807MEDIUM5.5A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox versi...
CVE-2021-21390MEDIUM5.9MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage se...
CVE-2021-27506MEDIUM5.5The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to Do...
CVE-2021-28090MEDIUM5.3Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TR...
CVE-2021-28126MEDIUM6.1index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vuln...
CVE-2021-25292MEDIUM6.5An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a craf...
CVE-2021-3327MEDIUM5.4Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter.
CVE-2021-28109MEDIUM6.1TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS).
CVE-2021-28653MEDIUM6.5The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They ...
CVE-2021-27436MEDIUM6.1WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malici...
CVE-2021-3416MEDIUM6A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and incl...
CVE-2021-25764MEDIUM5.3In JetBrains PhpStorm before 2020.3, source code could be added to debug logs.
CVE-2021-28160MEDIUM6.1Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value w...
CVE-2021-21383MEDIUM5.4Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scri...
CVE-2021-28796MEDIUM6.1Increments Qiita::Markdown before 0.33.0 allows XSS in transformers.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now