2021 CVE Vulnerabilities
23,451 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-20620 | MEDIUM | 6.1 | 1.0% | Jan 28, 2021 | Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an a... |
| CVE-2021-26067 | MEDIUM | 5.3 | 1.1% | Jan 28, 2021 | Affected versions of Atlassian Bamboo allow an unauthenticated remote attacker to view a stack trace that may reveal the... |
| CVE-2021-26276 | MEDIUM | 5.3 | 1.2% | Jan 27, 2021 | scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when pr... |
| CVE-2021-25226 | MEDIUM | 5.5 | 0.4% | Jan 27, 2021 | A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci... |
| CVE-2021-25225 | MEDIUM | 5.5 | 0.4% | Jan 27, 2021 | A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci... |
| CVE-2021-25224 | MEDIUM | 5.5 | 0.4% | Jan 27, 2021 | A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft speci... |
| CVE-2021-3318 | MEDIUM | 6.1 | 2.8% | Jan 27, 2021 | attach/ajax.php in DzzOffice through 2.02.1 allows XSS via the editorid parameter. |
| CVE-2021-20357 | MEDIUM | 5.4 | 0.7% | Jan 27, 2021 | IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary J... |
| CVE-2021-3272 | MEDIUM | 5.5 | 1.1% | Jan 27, 2021 | jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid rel... |
| CVE-2021-1071 | MEDIUM | 5.5 | 0.3% | Jan 26, 2021 | NVIDIA Tegra kernel in Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, all L4T versions prior t... |
| CVE-2021-26272 | MEDIUM | 6.5 | 2.2% | Jan 26, 2021 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL... |
| CVE-2021-26271 | MEDIUM | 6.5 | 2.0% | Jan 26, 2021 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted tex... |
| CVE-2021-21283 | MEDIUM | 5.4 | 0.8% | Jan 26, 2021 | Flarum is an open source discussion platform for websites. The "Flarum Sticky" extension versions 0.1.0-beta.14 and 0.1.... |
| CVE-2021-21271 | MEDIUM | 6.5 | 1.7% | Jan 26, 2021 | Tendermint Core is an open source Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine - writ... |
| CVE-2021-3308 | MEDIUM | 5.5 | 0.4% | Jan 26, 2021 | An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through d... |
| CVE-2021-23272 | MEDIUM | 5.4 | 0.5% | Jan 26, 2021 | The Application Development Clients component of TIBCO Software Inc.'s TIBCO BPM Enterprise and TIBCO BPM Enterprise Dis... |
| CVE-2021-3285 | MEDIUM | 5.3 | 1.1% | Jan 26, 2021 | jxbrowser in TI Code Composer Studio IDE 8.x through 10.x before 10.1.1 does not verify X.509 certificates for HTTPS. |
| CVE-2021-3186 | MEDIUM | 5.4 | 2.5% | Jan 26, 2021 | A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m... |
| CVE-2021-3152 | MEDIUM | 5.3 | 2.2% | Jan 26, 2021 | Home Assistant before 2021.1.3 does not have a protection layer that can help to prevent directory-traversal attacks aga... |
| CVE-2021-3114 | MEDIUM | 6.5 | 2.7% | Jan 26, 2021 | In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an und... |
| CVE-2021-25901 | MEDIUM | 5.3 | 1.3% | Jan 26, 2021 | An issue was discovered in the lazy-init crate through 2021-01-17 for Rust. Lazy lacks a Send bound, leading to a data r... |
| CVE-2021-22873 | MEDIUM | 6.1 | 66.1% | Jan 26, 2021 | Revive Adserver before 5.1.0 is vulnerable to open redirects via the `dest`, `oadest`, and/or `ct0` parameters of the lg... |
| CVE-2021-22872 | MEDIUM | 6.1 | 3.4% | Jan 26, 2021 | Revive Adserver before 5.1.0 is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the publicly acce... |
| CVE-2021-22871 | MEDIUM | 4.8 | 2.1% | Jan 26, 2021 | Revive Adserver before 5.1.0 permits any user with a manager account to store possibly malicious content in the URL webs... |
| CVE-2021-21615 | MEDIUM | 5.3 | 0.9% | Jan 26, 2021 | Jenkins 2.275 and LTS 2.263.2 allows reading arbitrary files using the file browser for workspaces and archived artifact... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now