2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22113 | MEDIUM | 5.3 | 0.8% | Feb 23, 2021 | Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vul... |
| CVE-2021-27550 | MEDIUM | 5.5 | 1.7% | Feb 23, 2021 | Polaris Office v9.102.66 is affected by a divide-by-zero error in PolarisOffice.exe and EngineDLL.dll that may cause a l... |
| CVE-2021-27568 | MEDIUM | 5.9 | 2.9% | Feb 23, 2021 | An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is throw... |
| CVE-2021-27189 | MEDIUM | 5.9 | 1.0% | Feb 23, 2021 | The CIRA Canadian Shield app before 4.0.13 for iOS lacks SSL Certificate Validation. |
| CVE-2021-23827 | MEDIUM | 5.5 | 0.3% | Feb 23, 2021 | Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potent... |
| CVE-2021-26725 | MEDIUM | 4.9 | 1.1% | Feb 22, 2021 | Path Traversal vulnerability when changing timezone using web GUI of Nozomi Networks Guardian, CMC allows an authenticat... |
| CVE-2021-27279 | MEDIUM | 5.4 | 1.0% | Feb 22, 2021 | MyBB before 1.8.25 allows stored XSS via nested [email] tags with MyCode (aka BBCode). |
| CVE-2021-27564 | MEDIUM | 5.4 | 0.5% | Feb 22, 2021 | A stored XSS issue exists in Appspace 6.2.4. After a user is authenticated and enters an XSS payload under the groups se... |
| CVE-2021-27549 | MEDIUM | 5.3 | 1.1% | Feb 22, 2021 | Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor... |
| CVE-2021-27559 | MEDIUM | 5.4 | 0.6% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field. |
| CVE-2021-27371 | MEDIUM | 5.4 | 0.6% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Description field. |
| CVE-2021-27370 | MEDIUM | 5.4 | 3.3% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field. |
| CVE-2021-27369 | MEDIUM | 5.4 | 0.6% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field. |
| CVE-2021-27368 | MEDIUM | 5.4 | 0.6% | Feb 22, 2021 | The Contact page in Monica 2.19.1 allows stored XSS via the First Name field. |
| CVE-2021-27515 | MEDIUM | 5.3 | 2.0% | Feb 22, 2021 | url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path. |
| CVE-2021-26716 | MEDIUM | 6.1 | 0.8% | Feb 21, 2021 | Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter. |
| CVE-2021-26544 | MEDIUM | 5.4 | 2.8% | Feb 20, 2021 | Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicio... |
| CVE-2021-3189 | MEDIUM | 6.1 | 0.5% | Feb 19, 2021 | The slashify package 1.0.0 for Node.js allows open-redirect attacks, as demonstrated by a localhost:3000///example.com/ ... |
| CVE-2021-26713 | MEDIUM | 6.5 | 1.8% | Feb 19, 2021 | A stack-based buffer overflow in res_rtp_asterisk.c in Sangoma Asterisk before 16.16.1, 17.x before 17.9.2, and 18.x bef... |
| CVE-2021-27351 | MEDIUM | 5.3 | 0.8% | Feb 19, 2021 | The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and U... |
| CVE-2021-27328 | MEDIUM | 6.5 | 9.0% | Feb 19, 2021 | Yeastar NeoGate TG400 91.3.0.3 devices are affected by Directory Traversal. An authenticated user can decrypt firmware a... |
| CVE-2021-27214 | MEDIUM | 6.1 | 2.0% | Feb 19, 2021 | A Server-side request forgery (SSRF) vulnerability in the ProductConfig servlet in Zoho ManageEngine ADSelfService Plus ... |
| CVE-2021-23342 | MEDIUM | 6.1 | 1.7% | Feb 19, 2021 | This affects the package docsify before 4.12.0. It is possible to bypass the remediation done by CVE-2020-7680 and execu... |
| CVE-2021-21512 | MEDIUM | 6 | 0.3% | Feb 19, 2021 | Dell EMC PowerProtect Cyber Recovery, version 19.7.0.1, contains an Information Disclosure vulnerability. A locally auth... |
| CVE-2021-22701 | MEDIUM | 4.5 | 0.3% | Feb 19, 2021 | A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION86... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now