2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21029 | MEDIUM | 4.8 | 84.7% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-s... |
| CVE-2021-21027 | MEDIUM | 4.3 | 1.7% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site reques... |
| CVE-2021-21026 | MEDIUM | 5.3 | 1.8% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authori... |
| CVE-2021-21023 | MEDIUM | 4.8 | 1.6% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-si... |
| CVE-2021-21022 | MEDIUM | 5.3 | 2.2% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc... |
| CVE-2021-21020 | MEDIUM | 5.3 | 2.4% | Feb 11, 2021 | Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control... |
| CVE-2021-25688 | MEDIUM | 5.5 | 0.2% | Feb 11, 2021 | Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux... |
| CVE-2021-22881 | MEDIUM | 6.1 | 87.3% | Feb 11, 2021 | The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Sp... |
| CVE-2021-21301 | MEDIUM | 4.3 | 0.9% | Feb 11, 2021 | Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerab... |
| CVE-2021-20404 | MEDIUM | 5.3 | 0.9% | Feb 11, 2021 | IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user on the network to cause a denial of service due... |
| CVE-2021-20335 | MEDIUM | 4.6 | 0.1% | Feb 11, 2021 | For MongoDB Ops Manager versions prior to and including 4.2.24 with multiple OM application servers, that have SSL turne... |
| CVE-2021-26938 | MEDIUM | 5.4 | 0.7% | Feb 10, 2021 | A stored XSS issue exists in henriquedornas 5.2.17 via online live chat. NOTE: Third parties report that no such product... |
| CVE-2021-0338 | MEDIUM | 5.5 | 0.1% | Feb 10, 2021 | In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings... |
| CVE-2021-0335 | MEDIUM | 6.5 | 0.8% | Feb 10, 2021 | In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to rem... |
| CVE-2021-23881 | MEDIUM | 4.8 | 0.6% | Feb 10, 2021 | A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February ... |
| CVE-2021-23873 | MEDIUM | 6.1 | 0.7% | Feb 10, 2021 | Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevate... |
| CVE-2021-23883 | MEDIUM | 4.4 | 0.3% | Feb 10, 2021 | A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Upd... |
| CVE-2021-23882 | MEDIUM | 4.4 | 0.3% | Feb 10, 2021 | Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update... |
| CVE-2021-23880 | MEDIUM | 4.4 | 0.3% | Feb 10, 2021 | Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update ... |
| CVE-2021-23878 | MEDIUM | 5 | 0.6% | Feb 10, 2021 | Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior ... |
| CVE-2021-20654 | MEDIUM | 5.4 | 0.8% | Feb 10, 2021 | Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scrip... |
| CVE-2021-26954 | MEDIUM | 5.3 | 1.4% | Feb 9, 2021 | An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can pe... |
| CVE-2021-21478 | MEDIUM | 6.1 | 0.9% | Feb 9, 2021 | SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities. |
| CVE-2021-21476 | MEDIUM | 6.1 | 0.8% | Feb 9, 2021 | SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated at... |
| CVE-2021-21474 | MEDIUM | 6.5 | 0.7% | Feb 9, 2021 | SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-di... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now