2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21029MEDIUM4.8Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a Reflected Cross-s...
CVE-2021-21027MEDIUM4.3Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by a cross-site reques...
CVE-2021-21026MEDIUM5.3Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are affected by an improper authori...
CVE-2021-21023MEDIUM4.8Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to a stored cross-si...
CVE-2021-21022MEDIUM5.3Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an insecure direc...
CVE-2021-21020MEDIUM5.3Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an access control...
CVE-2021-25688MEDIUM5.5Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux...
CVE-2021-22881MEDIUM6.1The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Sp...
CVE-2021-21301MEDIUM4.3Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerab...
CVE-2021-20404MEDIUM5.3IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user on the network to cause a denial of service due...
CVE-2021-20335MEDIUM4.6For MongoDB Ops Manager versions prior to and including 4.2.24 with multiple OM application servers, that have SSL turne...
CVE-2021-26938MEDIUM5.4A stored XSS issue exists in henriquedornas 5.2.17 via online live chat. NOTE: Third parties report that no such product...
CVE-2021-0338MEDIUM5.5In SystemSettingsValidators, there is a possible permanent denial of service due to missing bounds checks on UI settings...
CVE-2021-0335MEDIUM6.5In process of C2SoftHevcDec.cpp, there is a possible out of bounds write due to a use after free. This could lead to rem...
CVE-2021-23881MEDIUM4.8A stored cross site scripting vulnerability in ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 February ...
CVE-2021-23873MEDIUM6.1Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevate...
CVE-2021-23883MEDIUM4.4A Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Upd...
CVE-2021-23882MEDIUM4.4Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update...
CVE-2021-23880MEDIUM4.4Improper Access Control in attribute in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update ...
CVE-2021-23878MEDIUM5Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior ...
CVE-2021-20654MEDIUM5.4Wekan, open source kanban board system, between version 3.12 and 4.11, is vulnerable to multiple stored cross-site scrip...
CVE-2021-26954MEDIUM5.3An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can pe...
CVE-2021-21478MEDIUM6.1SAP Web Dynpro ABAP allow an attacker to redirect users to a malicious site due to Reverse Tabnabbing vulnerabilities.
CVE-2021-21476MEDIUM6.1SAP UI5 versions before 1.38.49, 1.52.49, 1.60.34, 1.71.31, 1.78.18, 1.84.5, 1.85.4, 1.86.1 allows an unauthenticated at...
CVE-2021-21474MEDIUM6.5SAP HANA Database, versions - 1.0, 2.0, accepts SAML tokens with MD5 digest, an attacker who manages to obtain an MD5-di...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now