2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-21444MEDIUM6.1SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options headers entries in the respo...
CVE-2021-26550MEDIUM5.5An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.
CVE-2021-26549MEDIUM5.4An XSS issue was discovered in SmartFoxServer 2.17.0. Input passed to the AdminTool console is not properly sanitized be...
CVE-2021-22267MEDIUM5.9Idelji Web ViewPoint Suite, as used in conjunction with HPE NonStop, allows a remote replay attack for T0320L01^ABP thro...
CVE-2021-25666MEDIUM4.3A vulnerability has been identified in SCALANCE W780 and W740 (IEEE 802.11n) family (All versions < V6.3). Sending speci...
CVE-2021-25141MEDIUM4.4A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error ...
CVE-2021-26676MEDIUM6.5gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing f...
CVE-2021-26921MEDIUM6.5In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disable...
CVE-2021-21147MEDIUM4.3Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the conte...
CVE-2021-26719MEDIUM6.5A directory traversal issue was discovered in Gradle gradle-enterprise-test-distribution-agent before 1.3.2, test-distri...
CVE-2021-21141MEDIUM6.5Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b...
CVE-2021-21140MEDIUM6.8Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of b...
CVE-2021-21139MEDIUM6.5Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypas...
CVE-2021-21137MEDIUM6.5Inappropriate implementation in DevTools in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to obtain pote...
CVE-2021-21136MEDIUM6.5Insufficient policy enforcement in WebView in Google Chrome on Android prior to 88.0.4324.96 allowed a remote attacker t...
CVE-2021-21135MEDIUM6.5Inappropriate implementation in Performance API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to leak...
CVE-2021-21134MEDIUM6.5Incorrect security UI in Page Info in Google Chrome on iOS prior to 88.0.4324.96 allowed a remote attacker to spoof secu...
CVE-2021-21133MEDIUM6.5Insufficient policy enforcement in Downloads in Google Chrome prior to 88.0.4324.96 allowed an attacker who convinced a ...
CVE-2021-21131MEDIUM6.5Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b...
CVE-2021-21130MEDIUM6.5Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b...
CVE-2021-21129MEDIUM6.5Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to b...
CVE-2021-21126MEDIUM6.5Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass...
CVE-2021-21123MEDIUM6.5Insufficient data validation in File System API in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypa...
CVE-2021-26925MEDIUM5.4Roundcube before 1.4.11 allows XSS via crafted Cascading Style Sheets (CSS) token sequences during HTML email rendering.
CVE-2021-23327MEDIUM6.3The package apexcharts before 3.24.0 are vulnerable to Cross-site Scripting (XSS) via lack of sanitization of graph lege...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now