2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21324 | MEDIUM | 6.5 | 1.4% | Mar 8, 2021 | GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses track... |
| CVE-2021-27222 | MEDIUM | 5.4 | 0.9% | Mar 8, 2021 | In the "Time in Status" app before 4.13.0 for Jira, remote authenticated attackers can cause Stored XSS. |
| CVE-2021-23351 | MEDIUM | 4.9 | 1.9% | Mar 8, 2021 | The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1(... |
| CVE-2021-27363 | MEDIUM | 4.4 | 0.7% | Mar 7, 2021 | An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address o... |
| CVE-2021-3377 | MEDIUM | 6.1 | 8.0% | Mar 5, 2021 | The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTM... |
| CVE-2021-27257 | MEDIUM | 6.5 | 0.3% | Mar 5, 2021 | This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected i... |
| CVE-2021-28039 | MEDIUM | 6.5 | 0.4% | Mar 5, 2021 | An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, ... |
| CVE-2021-28038 | MEDIUM | 6.5 | 0.7% | Mar 5, 2021 | An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver la... |
| CVE-2021-27099 | MEDIUM | 6.8 | 0.7% | Mar 5, 2021 | In SPIRE before versions 0.8.5, 0.9.4, 0.10.2, 0.11.3 and 0.12.1, the "aws_iid" Node Attestor improperly normalizes the ... |
| CVE-2021-26971 | MEDIUM | 6.3 | 1.3% | Mar 5, 2021 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver... |
| CVE-2021-26970 | MEDIUM | 6.3 | 1.3% | Mar 5, 2021 | A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver... |
| CVE-2021-26969 | MEDIUM | 6.5 | 1.4% | Mar 5, 2021 | A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management ... |
| CVE-2021-26968 | MEDIUM | 4.8 | 0.6% | Mar 5, 2021 | A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platfo... |
| CVE-2021-26967 | MEDIUM | 6.1 | 0.8% | Mar 5, 2021 | A remote reflected cross-site scripting (xss) vulnerability was discovered in Aruba AirWave Management Platform version(... |
| CVE-2021-26966 | MEDIUM | 6.5 | 1.1% | Mar 5, 2021 | A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior... |
| CVE-2021-26965 | MEDIUM | 6.5 | 1.1% | Mar 5, 2021 | A remote authenticated sql injection vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior... |
| CVE-2021-21725 | MEDIUM | 5.7 | 0.5% | Mar 5, 2021 | A ZTE product has an information leak vulnerability. An attacker with higher authority can go beyond their authority to ... |
| CVE-2021-27907 | MEDIUM | 5.4 | 86.4% | Mar 5, 2021 | Apache Superset up to and including 0.38.0 allowed the creation of a Markdown component on a Dashboard page for describi... |
| CVE-2021-20665 | MEDIUM | 6.1 | 0.8% | Mar 5, 2021 | Cross-site scripting vulnerability in in Add asset screen of Contents field of Movable Type 7 r.4705 and earlier (Movabl... |
| CVE-2021-20664 | MEDIUM | 6.1 | 0.8% | Mar 5, 2021 | Cross-site scripting vulnerability in in Asset registration screen of Movable Type 7 r.4705 and earlier (Movable Type 7 ... |
| CVE-2021-20663 | MEDIUM | 6.1 | 0.8% | Mar 5, 2021 | Cross-site scripting vulnerability in in Role authority setting screen of Movable Type 7 r.4705 and earlier (Movable Typ... |
| CVE-2021-25313 | MEDIUM | 6.1 | 1.5% | Mar 5, 2021 | A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rancher allows r... |
| CVE-2021-25347 | MEDIUM | 5.3 | 0.1% | Mar 4, 2021 | Hijacking vulnerability in Samsung Email application version prior to SMR Feb-2021 Release 1 allows attackers to interce... |
| CVE-2021-25345 | MEDIUM | 5.5 | 0.1% | Mar 4, 2021 | Graphic format mismatch while converting video format in hwcomposer prior to SMR Mar-2021 Release 1 results in kernel pa... |
| CVE-2021-25344 | MEDIUM | 5.5 | 0.1% | Mar 4, 2021 | Missing permission check in knox_custom service prior to SMR Mar-2021 Release 1 allows attackers to gain access to devic... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now