2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-27695 | MEDIUM | 6.1 | 3.0% | Mar 15, 2021 | Multiple stored cross-site scripting (XSS) vulnerabilities in openMAINT 2.1-3.3-b allow remote attackers to inject arbit... |
| CVE-2021-25675 | MEDIUM | 5.5 | 0.2% | Mar 15, 2021 | A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste... |
| CVE-2021-25674 | MEDIUM | 5.5 | 0.2% | Mar 15, 2021 | A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste... |
| CVE-2021-25673 | MEDIUM | 5.5 | 0.2% | Mar 15, 2021 | A vulnerability has been identified in SIMATIC S7-PLCSIM V5.4 (All versions). An attacker with local access to the syste... |
| CVE-2021-23357 | MEDIUM | 5.3 | 0.5% | Mar 15, 2021 | All versions of package github.com/tyktechnologies/tyk/gateway are vulnerable to Directory Traversal via the handleAddOr... |
| CVE-2021-3167 | MEDIUM | 6.5 | 1.1% | Mar 15, 2021 | In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster ser... |
| CVE-2021-20440 | MEDIUM | 4.3 | 0.7% | Mar 15, 2021 | IBM API Connect 10.0.0.0, and 2018.4.1.0 through 2018.4.1.13 does not restrict member registration to the intended recep... |
| CVE-2021-26924 | MEDIUM | 6.1 | 0.7% | Mar 15, 2021 | An issue was discovered in Argo CD before 1.8.4. Browser XSS protection is not activated due to the missing XSS protecti... |
| CVE-2021-27208 | MEDIUM | 6.8 | 0.4% | Mar 15, 2021 | When booting a Zync-7000 SOC device from nand flash memory, the nand driver in the ROM does not validate the inputs when... |
| CVE-2021-28378 | MEDIUM | 5.4 | 8.8% | Mar 15, 2021 | Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations. |
| CVE-2021-20018 | MEDIUM | 4.9 | 0.7% | Mar 13, 2021 | A post-authenticated vulnerability in SonicWall SMA100 allows an attacker to export the configuration file to the specif... |
| CVE-2021-28162 | MEDIUM | 6.1 | 0.8% | Mar 12, 2021 | In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascr... |
| CVE-2021-28161 | MEDIUM | 6.1 | 0.7% | Mar 12, 2021 | In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javasc... |
| CVE-2021-21080 | MEDIUM | 6.1 | 1.2% | Mar 12, 2021 | Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attac... |
| CVE-2021-21079 | MEDIUM | 6.1 | 1.1% | Mar 12, 2021 | Adobe Connect version 11.0.7 (and earlier) is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attac... |
| CVE-2021-21078 | MEDIUM | 6.5 | 1.1% | Mar 12, 2021 | Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability... |
| CVE-2021-21068 | MEDIUM | 6.1 | 0.6% | Mar 12, 2021 | Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a file handling vulnerability that cou... |
| CVE-2021-21379 | MEDIUM | 5.4 | 0.5% | Mar 12, 2021 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected ver... |
| CVE-2021-21366 | MEDIUM | 4.3 | 1.3% | Mar 12, 2021 | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom version... |
| CVE-2021-28153 | MEDIUM | 5.3 | 2.6% | Mar 11, 2021 | An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATIO... |
| CVE-2021-20261 | MEDIUM | 6.4 | 0.2% | Mar 11, 2021 | A race condition was found in the Linux kernels implementation of the floppy disk drive controller driver software. The ... |
| CVE-2021-28088 | MEDIUM | 5.4 | 0.9% | Mar 11, 2021 | Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to i... |
| CVE-2021-27679 | MEDIUM | 5.4 | 0.6% | Mar 11, 2021 | Cross-site scripting (XSS) vulnerability in Navigation in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary ... |
| CVE-2021-27678 | MEDIUM | 5.4 | 0.6% | Mar 11, 2021 | Cross-site scripting (XSS) vulnerability in Snippets in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary we... |
| CVE-2021-27677 | MEDIUM | 5.4 | 0.6% | Mar 11, 2021 | Cross-site scripting (XSS) vulnerability in Galleries in Batflat CMS 1.3.6 allows remote attackers to inject arbitrary w... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now