2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21973MEDIUM5.3The vSphere Client (HTML5) contains an SSRF (Server Side Request Forgery) vulnerability due to improper validation of UR...
CVE-2021-21622MEDIUM5.4Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulti...
CVE-2021-21621MEDIUM5.3Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (bas...
CVE-2021-21620MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Claim Plugin 2.18.1 and earlier allows attackers to change ...
CVE-2021-21619MEDIUM5.4Jenkins Claim Plugin 2.18.1 and earlier does not escape the user display name, resulting in a stored cross-site scriptin...
CVE-2021-21618MEDIUM5.4Jenkins Repository Connector Plugin 2.0.2 and earlier does not escape parameter names and descriptions for past builds, ...
CVE-2021-21616MEDIUM4.6Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-...
CVE-2021-3355MEDIUM5.4A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Tit...
CVE-2021-20660MEDIUM6.1Cross-site scripting vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to inject an ar...
CVE-2021-20657MEDIUM5.4Improper access control vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacke...
CVE-2021-20656MEDIUM4.3Exposure of information through directory listing in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authentic...
CVE-2021-3407MEDIUM5.5A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other pot...
CVE-2021-21323MEDIUM5.3Brave is an open source web browser with a focus on privacy and security. In Brave versions 1.17.73-1.20.103, the CNAME ...
CVE-2021-20256MEDIUM5.3A flaw was found in Red Hat Satellite. The BMC interface exposes the password through the API to an authenticated local ...
CVE-2021-20252MEDIUM6.5A flaw was found in Red Hat 3scale API Management Platform 2. The 3scale backend does not perform preventive handling on...
CVE-2021-3405MEDIUM6.5A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and E...
CVE-2021-26927MEDIUM5.5A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program cras...
CVE-2021-27583MEDIUM5.3In Directus 8.x through 8.8.1, an attacker can discover whether a user is present in the database through the password r...
CVE-2021-26595MEDIUM5.3In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP versi...
CVE-2021-26686MEDIUM6.5A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior t...
CVE-2021-26682MEDIUM6.1A remote reflected cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manager version(s):...
CVE-2021-26678MEDIUM6.1A remote unauthenticated stored cross-site scripting (XSS) vulnerability was discovered in Aruba ClearPass Policy Manage...
CVE-2021-20229MEDIUM4.3A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to c...
CVE-2021-20220MEDIUM4.8A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CV...
CVE-2021-26685MEDIUM6.5A remote authenticated SQL Injection vulnerabilitiy was discovered in Aruba ClearPass Policy Manager version(s): Prior t...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now