2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21173MEDIUM6.5Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker t...
CVE-2021-21171MEDIUM6.5Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 allowed a remote atta...
CVE-2021-21170MEDIUM6.5Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the...
CVE-2021-21168MEDIUM6.5Insufficient policy enforcement in appcache in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain p...
CVE-2021-21164MEDIUM6.5Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to...
CVE-2021-21163MEDIUM6.5Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to l...
CVE-2021-20262MEDIUM6.8A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows...
CVE-2021-20253MEDIUM6.7A flaw was found in ansible-tower. The default installation is vulnerable to Job Isolation escape allowing an attacker t...
CVE-2021-20243MEDIUM5.5A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by Imag...
CVE-2021-20241MEDIUM5.5A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick...
CVE-2021-3417MEDIUM4.9An internal product security audit of LXCO, prior to version 1.2.2, discovered that credentials for Lenovo XClarity Admi...
CVE-2021-21488MEDIUM6.5Knowledge Management versions 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 allows a remote attacker with basic privileges to deser...
CVE-2021-20341MEDIUM5.3IBM Cloud Pak for Multicloud Management Monitoring 2.2 returns potentially sensitive information in headers which could ...
CVE-2021-28006MEDIUM6.1Web Based Quiz System 1.0 is affected by cross-site scripting (XSS) in admin.php through the options parameter.
CVE-2021-24033MEDIUM5.6react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a c...
CVE-2021-21361MEDIUM6.5The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the loggi...
CVE-2021-21360MEDIUM5.3Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem arti...
CVE-2021-21510MEDIUM6.1Dell iDRAC8 versions prior to 2.75.100.75 contain a host header injection vulnerability. A remote unauthenticated attack...
CVE-2021-22134MEDIUM4.3A document disclosure flaw was found in Elasticsearch versions after 7.6.0 and before 7.11.0 when Document or Field Leve...
CVE-2021-21337MEDIUM6.1Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS...
CVE-2021-21336MEDIUM6.5Products.PluggableAuthService is a pluggable Zope authentication and authorization framework. In Products.PluggableAuthS...
CVE-2021-21362MEDIUM6.5MinIO is an open-source high performance object storage service and it is API compatible with Amazon S3 cloud storage se...
CVE-2021-21354MEDIUM6.1Pollbot is open source software which "frees its human masters from the toilsome task of polling for the state of things...
CVE-2021-21326MEDIUM6.5GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...
CVE-2021-21325MEDIUM4.8GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now