2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3204 | MEDIUM | 6.5 | 0.9% | Feb 19, 2021 | SSRF in the document conversion component of Webware Webdesktop 5.1.15 allows an attacker to read all files from the ser... |
| CVE-2021-3339 | MEDIUM | 4.3 | 1.9% | Feb 19, 2021 | ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the S... |
| CVE-2021-26746 | MEDIUM | 6.1 | 1.0% | Feb 19, 2021 | Chamilo 1.11.14 allows XSS via a main/calendar/agenda_list.php?type= URI. |
| CVE-2021-27404 | MEDIUM | 6.1 | 0.9% | Feb 19, 2021 | Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow injection of a Host HTTP header. |
| CVE-2021-27403 | MEDIUM | 6.1 | 1.2% | Feb 19, 2021 | Askey RTF8115VW BR_SV_g11.11_RTF_TEF001_V6.54_V014 devices allow cgi-bin/te_acceso_router.cgi curWebPage XSS. |
| CVE-2021-26906 | MEDIUM | 5.9 | 2.5% | Feb 18, 2021 | An issue was discovered in res_pjsip_session.c in Digium Asterisk through 13.38.1; 14.x, 15.x, and 16.x through 16.16.0;... |
| CVE-2021-3271 | MEDIUM | 4.8 | 0.9% | Feb 18, 2021 | PressBooks 5.17.3 contains a cross-site scripting (XSS). Stored XSS can be submitted via the Book Info's Long Descriptio... |
| CVE-2021-21318 | MEDIUM | 5.4 | 0.7% | Feb 18, 2021 | Opencast is a free, open-source platform to support the management of educational audio and video content. In Opencast b... |
| CVE-2021-20446 | MEDIUM | 5.4 | 0.5% | Feb 18, 2021 | IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2021-20445 | MEDIUM | 6.5 | 1.1% | Feb 18, 2021 | IBM Maximo for Civil Infrastructure 7.6.2 could allow a user to obtain sensitive information due to insecure storeage of... |
| CVE-2021-20444 | MEDIUM | 6.1 | 0.7% | Feb 18, 2021 | IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embe... |
| CVE-2021-27124 | MEDIUM | 6.5 | 5.7% | Feb 18, 2021 | SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated ... |
| CVE-2021-27375 | MEDIUM | 5.3 | 0.8% | Feb 18, 2021 | Traefik before 2.4.5 allows the loading of IFRAME elements from other domains. |
| CVE-2021-1416 | MEDIUM | 4.3 | 0.9% | Feb 17, 2021 | Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot... |
| CVE-2021-1412 | MEDIUM | 6.5 | 1.0% | Feb 17, 2021 | Multiple vulnerabilities in the Admin portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remot... |
| CVE-2021-1372 | MEDIUM | 5.5 | 0.4% | Feb 17, 2021 | A vulnerability in Cisco Webex Meetings Desktop App and Webex Productivity Tools for Windows could allow an authenticate... |
| CVE-2021-1351 | MEDIUM | 6.1 | 0.8% | Feb 17, 2021 | A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to co... |
| CVE-2021-26697 | MEDIUM | 5.3 | 4.6% | Feb 17, 2021 | The lineage endpoint of the deprecated Experimental API was not protected by authentication in Airflow 2.0.0. This allow... |
| CVE-2021-26559 | MEDIUM | 6.5 | 2.8% | Feb 17, 2021 | Improper Access Control on Configurations Endpoint for the Stable API of Apache Airflow allows users with Viewer or User... |
| CVE-2021-22853 | MEDIUM | 5.4 | 1.0% | Feb 17, 2021 | The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access ... |
| CVE-2021-23339 | MEDIUM | 6.5 | 0.7% | Feb 17, 2021 | This affects all versions before 10.1.14 and from 10.2.0 to 10.2.4 of package com.typesafe.akka:akka-http-core. It allow... |
| CVE-2021-20653 | MEDIUM | 5.3 | 1.2% | Feb 17, 2021 | Calsos CSDJ (CSDJ-B 01.08.00 and earlier, CSDJ-H 01.08.00 and earlier, CSDJ-D 01.08.00 and earlier, and CSDJ-A 03.08.00 ... |
| CVE-2021-26933 | MEDIUM | 5.5 | 0.3% | Feb 17, 2021 | An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are byp... |
| CVE-2021-26932 | MEDIUM | 5.5 | 0.3% | Feb 17, 2021 | An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in... |
| CVE-2021-26931 | MEDIUM | 5.5 | 0.5% | Feb 17, 2021 | An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consid... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now