2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-22113MEDIUM5.3Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vul...
CVE-2021-27550MEDIUM5.5Polaris Office v9.102.66 is affected by a divide-by-zero error in PolarisOffice.exe and EngineDLL.dll that may cause a l...
CVE-2021-27568MEDIUM5.9An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is throw...
CVE-2021-27189MEDIUM5.9The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation.
CVE-2021-23827MEDIUM5.5Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potent...
CVE-2021-26725MEDIUM4.9Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticat...
CVE-2021-27279MEDIUM5.4MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode).
CVE-2021-27564MEDIUM5.4A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups se...
CVE-2021-27549MEDIUM5.3Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor...
CVE-2021-27559MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.
CVE-2021-27371MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
CVE-2021-27370MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
CVE-2021-27369MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
CVE-2021-27368MEDIUM5.4The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.
CVE-2021-27515MEDIUM5.3url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.
CVE-2021-26716MEDIUM6.1Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.
CVE-2021-26544MEDIUM5.4Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicio...
CVE-2021-3189MEDIUM6.1The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ ...
CVE-2021-26713MEDIUM6.5A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x bef...
CVE-2021-27351MEDIUM5.3The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and U...
CVE-2021-27328MEDIUM6.5Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware a...
CVE-2021-27214MEDIUM6.1A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus ...
CVE-2021-23342MEDIUM6.1This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execu...
CVE-2021-21512MEDIUM6Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally auth...
CVE-2021-22701MEDIUM4.5A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION86...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now