2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-3294MEDIUM5.4CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a co...
CVE-2021-26917MEDIUM5.5PyBitmessage through 0.6.3.2 allows attackers to write screen captures to Potentially Unwanted Directories via a crafted...
CVE-2021-26916MEDIUM6.1In nopCommerce 4.30, a Reflected XSS issue in the Discount Coupon component allows remote attackers to inject arbitrary ...
CVE-2021-26905MEDIUM6.51Password SCIM Bridge before 1.6.2 mishandles validation of authenticated requests for log files, leading to disclosure ...
CVE-2021-21290MEDIUM5.5Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable h...
CVE-2021-21288MEDIUM4.3CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. I...
CVE-2021-26540MEDIUM5.3Apostrophe Technologies sanitize-html before 2.3.2 does not properly validate the hostnames set by the "allowedIframeHos...
CVE-2021-26539MEDIUM5.3Apostrophe Technologies sanitize-html before 2.3.1 does not properly handle internationalized domain name (IDN) which co...
CVE-2021-22122MEDIUM6.1An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version...
CVE-2021-3293MEDIUM5.3emlog v5.3.1 has full path disclosure vulnerability in t/index.php, which allows an attacker to see the path to the webr...
CVE-2021-20359MEDIUM6.5IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentiall...
CVE-2021-20358MEDIUM6.5IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 stores potentially sensitive information in clear text in API connecti...
CVE-2021-21436MEDIUM4.3Agents are able to see and link Config Items without permissions, which are defined in General Catalog. This issue affec...
CVE-2021-21435MEDIUM6.5Article Bcc fields and agent personal information are shown when customer prints the ticket (PDF) via external interface...
CVE-2021-21434MEDIUM4.8Survey administrator can craft a survey in such way that malicious code can be executed in the agent interface (i.e. ano...
CVE-2021-22161MEDIUM6.5In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur that generates excessive network traffic ...
CVE-2021-26723MEDIUM6.1Jenzabar 9.2.x through 9.2.2 allows /ics?tool=search&query= XSS.
CVE-2021-22500MEDIUM6.5Cross Site Request Forgery vulnerability in Micro Focus Application Performance Management product, affecting versions 9...
CVE-2021-22298MEDIUM6.5There is a logic vulnerability in Huawei Gauss100 OLTP Product. An attacker with certain permissions could perform speci...
CVE-2021-22499MEDIUM4.8Persistent Cross-Site scripting vulnerability in Micro Focus Application Performance Management product, affecting versi...
CVE-2021-22306MEDIUM4.6There is an out-of-bound read vulnerability in Mate 30 10.0.0.182(C00E180R6P2). A module does not verify the some input ...
CVE-2021-22300MEDIUM4.1There is an information leak vulnerability in eCNS280_TD versions V100R005C00 and V100R005C10. A command does not have t...
CVE-2021-22307MEDIUM5.5There is a weak algorithm vulnerability in Mate 3010.0.0.203(C00E201R7P2). The protection is insufficient for the module...
CVE-2021-22301MEDIUM6.7Mate 30 10.0.0.203(C00E201R7P2) have a buffer overflow vulnerability. After obtaining the root permission, an attacker c...
CVE-2021-20176MEDIUM5.5A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an attacker who submit...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now