2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-3294 | MEDIUM | 5.4 | 3.0% | Feb 9, 2021 | CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a co... |
| CVE-2021-26917 | MEDIUM | 5.5 | 0.5% | Feb 8, 2021 | PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted... |
| CVE-2021-26916 | MEDIUM | 6.1 | 1.1% | Feb 8, 2021 | In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary ... |
| CVE-2021-26905 | MEDIUM | 6.5 | 1.0% | Feb 8, 2021 | 1Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure ... |
| CVE-2021-21290 | MEDIUM | 5.5 | 1.8% | Feb 8, 2021 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h... |
| CVE-2021-21288 | MEDIUM | 4.3 | 1.2% | Feb 8, 2021 | CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. I... |
| CVE-2021-26540 | MEDIUM | 5.3 | 1.8% | Feb 8, 2021 | Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHos... |
| CVE-2021-26539 | MEDIUM | 5.3 | 2.0% | Feb 8, 2021 | Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which co... |
| CVE-2021-22122 | MEDIUM | 6.1 | 10.5% | Feb 8, 2021 | An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version... |
| CVE-2021-3293 | MEDIUM | 5.3 | 17.4% | Feb 8, 2021 | emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webr... |
| CVE-2021-20359 | MEDIUM | 6.5 | 1.3% | Feb 8, 2021 | IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentiall... |
| CVE-2021-20358 | MEDIUM | 6.5 | 0.8% | Feb 8, 2021 | IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connecti... |
| CVE-2021-21436 | MEDIUM | 4.3 | 0.8% | Feb 8, 2021 | Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affec... |
| CVE-2021-21435 | MEDIUM | 6.5 | 1.3% | Feb 8, 2021 | Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface... |
| CVE-2021-21434 | MEDIUM | 4.8 | 0.7% | Feb 8, 2021 | Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. ano... |
| CVE-2021-22161 | MEDIUM | 6.5 | 0.5% | Feb 7, 2021 | In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur that generates excessive network traffic ... |
| CVE-2021-26723 | MEDIUM | 6.1 | 10.9% | Feb 6, 2021 | Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS. |
| CVE-2021-22500 | MEDIUM | 6.5 | 0.5% | Feb 6, 2021 | Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9... |
| CVE-2021-22298 | MEDIUM | 6.5 | 0.9% | Feb 6, 2021 | There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform speci... |
| CVE-2021-22499 | MEDIUM | 4.8 | 0.6% | Feb 6, 2021 | Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versi... |
| CVE-2021-22306 | MEDIUM | 4.6 | 0.2% | Feb 6, 2021 | There is an out-of-bound read vulnerability in Mate 30 10.0.0.182(C00E180R6P2). A module does not verify the some input ... |
| CVE-2021-22300 | MEDIUM | 4.1 | 0.1% | Feb 6, 2021 | There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have t... |
| CVE-2021-22307 | MEDIUM | 5.5 | 0.2% | Feb 6, 2021 | There is a weak algorithm vulnerability in Mate 3010.0.0.203(C00E201R7P2). The protection is insufficient for the module... |
| CVE-2021-22301 | MEDIUM | 6.7 | 0.2% | Feb 6, 2021 | Mate 30 10.0.0.203(C00E201R7P2) have a buffer overflow vulnerability. After obtaining the root permission, an attacker c... |
| CVE-2021-20176 | MEDIUM | 5.5 | 0.9% | Feb 6, 2021 | A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an attacker who submit... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now