2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-26989 | MEDIUM | 6.5 | 1.1% | Mar 4, 2021 | Clustered Data ONTAP versions prior to 9.3P21, 9.5P16, 9.6P12, 9.7P9 and 9.8 are susceptible to a vulnerability which co... |
| CVE-2021-25339 | MEDIUM | 5.2 | 0.1% | Mar 4, 2021 | Improper address validation in HArx in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, given ... |
| CVE-2021-25338 | MEDIUM | 5.2 | 0.1% | Mar 4, 2021 | Improper memory access control in RKP in Samsung mobile devices prior to SMR Mar-2021 Release 1 allows an attacker, give... |
| CVE-2021-25334 | MEDIUM | 5.5 | 0.1% | Mar 4, 2021 | Improper input check in wallpaper service in Samsung mobile devices prior to SMR Feb-2021 Release 1 allows untrusted app... |
| CVE-2021-24032 | MEDIUM | 4.7 | 0.3% | Mar 4, 2021 | Beginning in v1.4.1 and prior to v1.4.9, due to an incomplete fix for CVE-2021-24031, the Zstandard command-line utility... |
| CVE-2021-24031 | MEDIUM | 5.5 | 0.4% | Mar 4, 2021 | In the Zstandard command-line utility prior to v1.4.1, output files were created with default permissions. Correct file ... |
| CVE-2021-20351 | MEDIUM | 5.4 | 0.5% | Mar 4, 2021 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java... |
| CVE-2021-20350 | MEDIUM | 5.4 | 0.5% | Mar 4, 2021 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java... |
| CVE-2021-20340 | MEDIUM | 5.4 | 0.5% | Mar 4, 2021 | IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Java... |
| CVE-2021-27217 | MEDIUM | 4.4 | 1.6% | Mar 4, 2021 | An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not ... |
| CVE-2021-26029 | MEDIUM | 5.3 | 1.1% | Mar 4, 2021 | An issue was discovered in Joomla! 1.6.0 through 3.9.24. Inadequate filtering of form contents could allow to overwrite ... |
| CVE-2021-26028 | MEDIUM | 5.5 | 1.2% | Mar 4, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.24. Extracting an specifilcy crafted zip package could write files ... |
| CVE-2021-26027 | MEDIUM | 5.3 | 1.1% | Mar 4, 2021 | An issue was discovered in Joomla! 3.0.0 through 3.9.24. Incorrect ACL checks could allow unauthorized change of the cat... |
| CVE-2021-23130 | MEDIUM | 6.1 | 0.9% | Mar 4, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of feed fields could lead to xss issues. |
| CVE-2021-23129 | MEDIUM | 6.1 | 0.9% | Mar 4, 2021 | An issue was discovered in Joomla! 2.5.0 through 3.9.24. Missing filtering of messages showed to users that could lead t... |
| CVE-2021-23126 | MEDIUM | 5.3 | 1.3% | Mar 4, 2021 | An issue was discovered in Joomla! 3.2.0 through 3.9.24. Usage of the insecure rand() function within the process of gen... |
| CVE-2021-22128 | MEDIUM | 4.3 | 1.0% | Mar 4, 2021 | An improper access control vulnerability in FortiProxy SSL VPN portal 2.0.0, 1.2.9 and below versions may allow an authe... |
| CVE-2021-23346 | MEDIUM | 5.3 | 2.2% | Mar 4, 2021 | This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certa... |
| CVE-2021-22183 | MEDIUM | 5.4 | 0.8% | Mar 4, 2021 | An issue has been discovered in GitLab affecting all versions starting with 11.8. GitLab was vulnerable to a stored XSS ... |
| CVE-2021-27940 | MEDIUM | 6.1 | 1.2% | Mar 3, 2021 | resources/public/js/orchestrator.js in openark orchestrator before 3.2.4 allows XSS via the orchestrator-msg parameter. |
| CVE-2021-21314 | MEDIUM | 4.8 | 0.6% | Mar 3, 2021 | GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana... |
| CVE-2021-21313 | MEDIUM | 6.1 | 0.9% | Mar 3, 2021 | GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana... |
| CVE-2021-21312 | MEDIUM | 4.8 | 0.6% | Mar 3, 2021 | GLPI is open source software which stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Mana... |
| CVE-2021-27839 | MEDIUM | 4.4 | 0.7% | Mar 3, 2021 | A CSV injection vulnerability found in Online Invoicing System (OIS) 4.3 and below can be exploited by users to perform ... |
| CVE-2021-22878 | MEDIUM | 4.8 | 1.1% | Mar 3, 2021 | Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `O... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now