2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-20634MEDIUM4.3Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to ...
CVE-2021-20633MEDIUM4.3Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to byp...
CVE-2021-20632MEDIUM4.3Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers...
CVE-2021-20631MEDIUM6.5Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to...
CVE-2021-20630MEDIUM4.3Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers...
CVE-2021-20629MEDIUM6.1Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbi...
CVE-2021-20628MEDIUM6.1Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a...
CVE-2021-20627MEDIUM6.1Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a...
CVE-2021-20626MEDIUM6.5Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to by...
CVE-2021-20625MEDIUM4.3Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attack...
CVE-2021-20624MEDIUM6.5Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to...
CVE-2021-28650MEDIUM5.5autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Dire...
CVE-2021-28380MEDIUM5.4The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows...
CVE-2021-27938MEDIUM6.1A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs modu...
CVE-2021-3418MEDIUM6.4If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel withou...
CVE-2021-20283MEDIUM4.3The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had per...
CVE-2021-20282MEDIUM5.3When creating a user account, it was possible to verify the account without having access to the verification email link...
CVE-2021-20281MEDIUM5.3It was possible for some users without permission to view other users' full names to do so via the online users block in...
CVE-2021-20280MEDIUM5.4Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3...
CVE-2021-20279MEDIUM5.4The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3....
CVE-2021-3150MEDIUM6.1A cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an ...
CVE-2021-23879MEDIUM6.7Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrat...
CVE-2021-28363MEDIUM6.5The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HT...
CVE-2021-27949MEDIUM6.1Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools.
CVE-2021-27889MEDIUM6.1Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now