2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21973 | MEDIUM | 5.3 | 88.0% | Feb 24, 2021 | The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR... |
| CVE-2021-21622 | MEDIUM | 5.4 | 9.4% | Feb 24, 2021 | Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulti... |
| CVE-2021-21621 | MEDIUM | 5.3 | 1.2% | Feb 24, 2021 | Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (bas... |
| CVE-2021-21620 | MEDIUM | 4.3 | 1.6% | Feb 24, 2021 | A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change ... |
| CVE-2021-21619 | MEDIUM | 5.4 | 9.4% | Feb 24, 2021 | Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scriptin... |
| CVE-2021-21618 | MEDIUM | 5.4 | 82.2% | Feb 24, 2021 | Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, ... |
| CVE-2021-21616 | MEDIUM | 4.6 | 78.8% | Feb 24, 2021 | Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-... |
| CVE-2021-3355 | MEDIUM | 5.4 | 7.3% | Feb 24, 2021 | A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Tit... |
| CVE-2021-20660 | MEDIUM | 6.1 | 46.9% | Feb 24, 2021 | Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an ar... |
| CVE-2021-20657 | MEDIUM | 5.4 | 2.7% | Feb 24, 2021 | Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacke... |
| CVE-2021-20656 | MEDIUM | 4.3 | 1.1% | Feb 24, 2021 | Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authentic... |
| CVE-2021-3407 | MEDIUM | 5.5 | 50.5% | Feb 23, 2021 | A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other pot... |
| CVE-2021-21323 | MEDIUM | 5.3 | 1.9% | Feb 23, 2021 | Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME ... |
| CVE-2021-20256 | MEDIUM | 5.3 | 0.3% | Feb 23, 2021 | A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local ... |
| CVE-2021-20252 | MEDIUM | 6.5 | 1.0% | Feb 23, 2021 | A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on... |
| CVE-2021-3405 | MEDIUM | 6.5 | 1.7% | Feb 23, 2021 | A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and E... |
| CVE-2021-26927 | MEDIUM | 5.5 | 1.1% | Feb 23, 2021 | A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program cras... |
| CVE-2021-27583 | MEDIUM | 5.3 | 1.1% | Feb 23, 2021 | In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password r... |
| CVE-2021-26595 | MEDIUM | 5.3 | 0.7% | Feb 23, 2021 | In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP versi... |
| CVE-2021-26686 | MEDIUM | 6.5 | 1.2% | Feb 23, 2021 | A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior t... |
| CVE-2021-26682 | MEDIUM | 6.1 | 0.8% | Feb 23, 2021 | A remote reflected cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s):... |
| CVE-2021-26678 | MEDIUM | 6.1 | 0.9% | Feb 23, 2021 | A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manage... |
| CVE-2021-20229 | MEDIUM | 4.3 | 1.5% | Feb 23, 2021 | A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to c... |
| CVE-2021-20220 | MEDIUM | 4.8 | 1.1% | Feb 23, 2021 | A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CV... |
| CVE-2021-26685 | MEDIUM | 6.5 | 1.1% | Feb 23, 2021 | A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior t... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now