2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26069 | MEDIUM | 5.3 | 2.5% | Mar 22, 2021 | Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to download temporary ... |
| CVE-2021-28957 | MEDIUM | 6.1 | 4.0% | Mar 21, 2021 | An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3. When disabling the safe_attrs_o... |
| CVE-2021-28951 | MEDIUM | 5.5 | 0.3% | Mar 20, 2021 | An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of se... |
| CVE-2021-28950 | MEDIUM | 5.5 | 0.4% | Mar 20, 2021 | An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retr... |
| CVE-2021-27520 | MEDIUM | 6.1 | 6.4% | Mar 19, 2021 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "... |
| CVE-2021-27519 | MEDIUM | 6.1 | 7.6% | Mar 19, 2021 | A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "... |
| CVE-2021-20077 | MEDIUM | 6.7 | 0.3% | Mar 19, 2021 | Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local h... |
| CVE-2021-25278 | MEDIUM | 4.8 | 0.6% | Mar 19, 2021 | FTAPI 4.0 through 4.10 allows XSS via an SVG document to the Background Image upload feature in the Submit Box Template ... |
| CVE-2021-25277 | MEDIUM | 6.1 | 0.8% | Mar 19, 2021 | FTAPI 4.0 - 4.10 allows XSS via a crafted filename to the alternative text hover box in the file submission component. |
| CVE-2021-27906 | MEDIUM | 5.5 | 3.3% | Mar 19, 2021 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFB... |
| CVE-2021-27807 | MEDIUM | 5.5 | 3.0% | Mar 19, 2021 | A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox versi... |
| CVE-2021-21390 | MEDIUM | 5.9 | 0.9% | Mar 19, 2021 | MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage se... |
| CVE-2021-27506 | MEDIUM | 5.5 | 1.3% | Mar 19, 2021 | The ClamAV Engine (version 0.103.1 and below) component embedded in Storsmshield Network Security (SNS) is subject to Do... |
| CVE-2021-28090 | MEDIUM | 5.3 | 2.1% | Mar 19, 2021 | Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TR... |
| CVE-2021-28126 | MEDIUM | 6.1 | 0.6% | Mar 19, 2021 | index.jsp in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a Stored cross-site scripting (XSS) vuln... |
| CVE-2021-25292 | MEDIUM | 6.5 | 1.6% | Mar 19, 2021 | An issue was discovered in Pillow before 8.1.1. The PDF parser allows a regular expression DoS (ReDoS) attack via a craf... |
| CVE-2021-3327 | MEDIUM | 5.4 | 0.7% | Mar 19, 2021 | Ovation Dynamic Content 1.10.1 for Elementor allows XSS via the post_title parameter. |
| CVE-2021-28109 | MEDIUM | 6.1 | 0.7% | Mar 19, 2021 | TranzWare (POI) FIMI before 4.2.20.4.2 allows login_tw.php reflected Cross-Site Scripting (XSS). |
| CVE-2021-28653 | MEDIUM | 6.5 | 0.9% | Mar 19, 2021 | The iOS and macOS apps before 1.4.1 for the Western Digital G-Technology ArmorLock NVMe SSD store keys insecurely. They ... |
| CVE-2021-27436 | MEDIUM | 6.1 | 0.7% | Mar 18, 2021 | WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malici... |
| CVE-2021-3416 | MEDIUM | 6 | 0.5% | Mar 18, 2021 | A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and incl... |
| CVE-2021-25764 | MEDIUM | 5.3 | 0.8% | Mar 18, 2021 | In JetBrains PhpStorm before 2020.3, source code could be added to debug logs. |
| CVE-2021-28160 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Wireless-N WiFi Repeater REV 1.0 (28.08.06.1) suffers from a reflected XSS vulnerability due to unsanitized SSID value w... |
| CVE-2021-21383 | MEDIUM | 5.4 | 0.9% | Mar 18, 2021 | Wiki.js an open-source wiki app built on Node.js. Wiki.js before version 2.5.191 is vulnerable to stored cross-site scri... |
| CVE-2021-28796 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Increments Qiita::Markdown before 0.33.0 allows XSS in transformers. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now