2021 CVE Vulnerabilities

23,452 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-23933MEDIUM6.1OX App Suite through 7.10.4 allows XSS via JavaScript in a Note referenced by a mail:// URL.
CVE-2021-23932MEDIUM6.1OX App Suite through 7.10.4 allows XSS via an inline image with a crafted filename.
CVE-2021-23931MEDIUM6.1OX App Suite through 7.10.4 allows XSS via an inline binary file.
CVE-2021-23930MEDIUM6.1OX App Suite through 7.10.4 allows XSS via use of the conversion API for a distributedFile.
CVE-2021-23929MEDIUM6.1OX App Suite through 7.10.4 allows XSS via a crafted Content-Disposition header in an uploaded HTML document to an ajax/...
CVE-2021-23928MEDIUM6.1OX App Suite through 7.10.3 allows XSS via the ajax/apps/manifests query string.
CVE-2021-23927MEDIUM6.4OX App Suite through 7.10.4 allows SSRF via a URL with an @ character in an appsuite/api/oauth/proxy PUT request.
CVE-2021-23125MEDIUM6.1An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple co...
CVE-2021-23124MEDIUM6.1An issue was discovered in Joomla! 3.9.0 through 3.9.23. The lack of escaping in mod_breadcrumbs aria-label attribute al...
CVE-2021-23123MEDIUM5.3An issue was discovered in Joomla! 3.0.0 through 3.9.23. The lack of ACL checks in the orderPosition endpoint of com_mod...
CVE-2021-1725MEDIUM5.5Bot Framework SDK Information Disclosure Vulnerability
CVE-2021-1717MEDIUM4.6Microsoft SharePoint Server Spoofing Vulnerability
CVE-2021-1708MEDIUM5.7Windows GDI+ Information Disclosure Vulnerability
CVE-2021-1705MEDIUM4.2Microsoft Edge (HTML-based) Memory Corruption Vulnerability
CVE-2021-1699MEDIUM5.5Windows (modem.sys) Information Disclosure Vulnerability
CVE-2021-1696MEDIUM5.5Windows Graphics Component Information Disclosure Vulnerability
CVE-2021-1684MEDIUM5Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information re...
CVE-2021-1683MEDIUM5Microsoft is aware of the "Impersonation in the Passkey Entry Protocol" vulnerability. For more information re...
CVE-2021-1679MEDIUM6.5Windows CryptoAPI Denial of Service Vulnerability
CVE-2021-1677MEDIUM5.5Azure Active Directory Pod Identity Spoofing Vulnerability
CVE-2021-1676MEDIUM5.5Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability
CVE-2021-1672MEDIUM5.5Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
CVE-2021-1670MEDIUM5.5Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
CVE-2021-1663MEDIUM5.5Windows Projected File System FS Filter Driver Information Disclosure Vulnerability
CVE-2021-1656MEDIUM5.5TPM Device Driver Information Disclosure Vulnerability

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now