2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-21444 | MEDIUM | 6.1 | 0.8% | Feb 9, 2021 | SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the respo... |
| CVE-2021-26550 | MEDIUM | 5.5 | 0.4% | Feb 9, 2021 | An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml. |
| CVE-2021-26549 | MEDIUM | 5.4 | 1.3% | Feb 9, 2021 | An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized be... |
| CVE-2021-22267 | MEDIUM | 5.9 | 1.4% | Feb 9, 2021 | Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP thro... |
| CVE-2021-25666 | MEDIUM | 4.3 | 0.7% | Feb 9, 2021 | A vulnerability has been identified in SCALANCE W780 and W740 (IEEE 802.11n) family (All versions < V6.3). Sending speci... |
| CVE-2021-25141 | MEDIUM | 4.4 | 0.3% | Feb 9, 2021 | A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error ... |
| CVE-2021-26676 | MEDIUM | 6.5 | 1.2% | Feb 9, 2021 | gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing f... |
| CVE-2021-26921 | MEDIUM | 6.5 | 1.3% | Feb 9, 2021 | In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disable... |
| CVE-2021-21147 | MEDIUM | 4.3 | 0.8% | Feb 9, 2021 | Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the conte... |
| CVE-2021-26719 | MEDIUM | 6.5 | 1.4% | Feb 9, 2021 | A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distri... |
| CVE-2021-21141 | MEDIUM | 6.5 | 5.4% | Feb 9, 2021 | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b... |
| CVE-2021-21140 | MEDIUM | 6.8 | 0.8% | Feb 9, 2021 | Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of b... |
| CVE-2021-21139 | MEDIUM | 6.5 | 4.7% | Feb 9, 2021 | Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypas... |
| CVE-2021-21137 | MEDIUM | 6.5 | 5.9% | Feb 9, 2021 | Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain pote... |
| CVE-2021-21136 | MEDIUM | 6.5 | 4.2% | Feb 9, 2021 | Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker t... |
| CVE-2021-21135 | MEDIUM | 6.5 | 19.2% | Feb 9, 2021 | Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak... |
| CVE-2021-21134 | MEDIUM | 6.5 | 5.0% | Feb 9, 2021 | Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof secu... |
| CVE-2021-21133 | MEDIUM | 6.5 | 3.0% | Feb 9, 2021 | Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a ... |
| CVE-2021-21131 | MEDIUM | 6.5 | 8.0% | Feb 9, 2021 | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b... |
| CVE-2021-21130 | MEDIUM | 6.5 | 5.4% | Feb 9, 2021 | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b... |
| CVE-2021-21129 | MEDIUM | 6.5 | 5.4% | Feb 9, 2021 | Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b... |
| CVE-2021-21126 | MEDIUM | 6.5 | 8.7% | Feb 9, 2021 | Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass... |
| CVE-2021-21123 | MEDIUM | 6.5 | 10.0% | Feb 9, 2021 | Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypa... |
| CVE-2021-26925 | MEDIUM | 5.4 | 1.0% | Feb 9, 2021 | Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering. |
| CVE-2021-23327 | MEDIUM | 6.3 | 1.4% | Feb 9, 2021 | The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph lege... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now