2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20634 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to ... |
| CVE-2021-20633 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Cabinet of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to byp... |
| CVE-2021-20632 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers... |
| CVE-2021-20631 | MEDIUM | 6.5 | 0.7% | Mar 18, 2021 | Improper input validation vulnerability in Custom App of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attacker to... |
| CVE-2021-20630 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers... |
| CVE-2021-20629 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Cross-site scripting vulnerability in E-mail of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject an arbi... |
| CVE-2021-20628 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a... |
| CVE-2021-20627 | MEDIUM | 6.1 | 0.8% | Mar 18, 2021 | Cross-site scripting vulnerability in Address Book of Cybozu Office 10.0.0 to 10.8.4 allows remote attackers to inject a... |
| CVE-2021-20626 | MEDIUM | 6.5 | 0.8% | Mar 18, 2021 | Improper access control vulnerability in Workflow of Cybozu Office 10.0.0 to 10.8.4 allows authenticated attackers to by... |
| CVE-2021-20625 | MEDIUM | 4.3 | 0.7% | Mar 18, 2021 | Improper access control vulnerability in Bulletin Board of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attack... |
| CVE-2021-20624 | MEDIUM | 6.5 | 0.8% | Mar 18, 2021 | Improper access control vulnerability in Scheduler of Cybozu Office 10.0.0 to 10.8.4 allows an authenticated attacker to... |
| CVE-2021-28650 | MEDIUM | 5.5 | 0.5% | Mar 17, 2021 | autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Dire... |
| CVE-2021-28380 | MEDIUM | 5.4 | 0.5% | Mar 16, 2021 | The aimeos (aka Aimeos shop and e-commerce framework) extension before 19.10.12 and 20.x before 20.10.5 for TYPO3 allows... |
| CVE-2021-27938 | MEDIUM | 6.1 | 0.8% | Mar 16, 2021 | A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs modu... |
| CVE-2021-3418 | MEDIUM | 6.4 | 0.5% | Mar 15, 2021 | If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel withou... |
| CVE-2021-20283 | MEDIUM | 4.3 | 1.1% | Mar 15, 2021 | The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had per... |
| CVE-2021-20282 | MEDIUM | 5.3 | 1.3% | Mar 15, 2021 | When creating a user account, it was possible to verify the account without having access to the verification email link... |
| CVE-2021-20281 | MEDIUM | 5.3 | 1.3% | Mar 15, 2021 | It was possible for some users without permission to view other users' full names to do so via the online users block in... |
| CVE-2021-20280 | MEDIUM | 5.4 | 1.3% | Mar 15, 2021 | Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3... |
| CVE-2021-20279 | MEDIUM | 5.4 | 1.0% | Mar 15, 2021 | The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.... |
| CVE-2021-3150 | MEDIUM | 6.1 | 0.6% | Mar 15, 2021 | A cross-site scripting (XSS) vulnerability on the Delete Personal Data page in Cryptshare Server before 4.8.0 allows an ... |
| CVE-2021-23879 | MEDIUM | 6.7 | 0.3% | Mar 15, 2021 | Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrat... |
| CVE-2021-28363 | MEDIUM | 6.5 | 2.1% | Mar 15, 2021 | The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HT... |
| CVE-2021-27949 | MEDIUM | 6.1 | 0.6% | Mar 15, 2021 | Cross-site Scripting vulnerability in MyBB before 1.8.26 via Custom moderator tools. |
| CVE-2021-27889 | MEDIUM | 6.1 | 5.1% | Mar 15, 2021 | Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages. |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now