2021 CVE Vulnerabilities
23,445 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45721 | MEDIUM | 6.1 | 0.5% | Jul 6, 2022 | JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one ... |
| CVE-2021-25066 | MEDIUM | 4.8 | 0.5% | Jul 4, 2022 | The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing hi... |
| CVE-2021-25056 | MEDIUM | 4.8 | 0.5% | Jul 4, 2022 | The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high pri... |
| CVE-2021-37524 | MEDIUM | 6.1 | 0.7% | Jul 1, 2022 | Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web... |
| CVE-2021-38954 | MEDIUM | 4.3 | 0.6% | Jun 30, 2022 | IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could disclose sensitiv... |
| CVE-2021-37791 | MEDIUM | 4.9 | 0.7% | Jun 30, 2022 | MyAdmin v1.0 is affected by an incorrect access control vulnerability in viewing personal center in /api/user/userData?u... |
| CVE-2021-39074 | MEDIUM | 6.1 | 0.5% | Jun 29, 2022 | IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav... |
| CVE-2021-40642 | MEDIUM | 4.3 | 0.4% | Jun 29, 2022 | Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribu... |
| CVE-2021-41559 | MEDIUM | 6.5 | 1.0% | Jun 28, 2022 | Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack vi... |
| CVE-2021-3779 | MEDIUM | 6.5 | 1.1% | Jun 28, 2022 | A malicious MySQL server can request local file content from a client using ruby-mysql prior to version 2.10.0 without e... |
| CVE-2021-40944 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_... |
| CVE-2021-40943 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in A... |
| CVE-2021-40609 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box ... |
| CVE-2021-40608 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in ... |
| CVE-2021-40607 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box ... |
| CVE-2021-40606 | MEDIUM | 5.5 | 0.6% | Jun 28, 2022 | The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4B... |
| CVE-2021-40942 | MEDIUM | 5.5 | 0.6% | Jun 27, 2022 | In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filter_parse_dyn_args function in filter_core/fil... |
| CVE-2021-42056 | MEDIUM | 6.7 | 1.0% | Jun 24, 2022 | Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock ... |
| CVE-2021-39408 | MEDIUM | 6.1 | 1.3% | Jun 24, 2022 | Cross Site Scripting (XSS) vulnerability exists in Online Student Rate System 1.0 via the page parameter on the index.ph... |
| CVE-2021-38879 | MEDIUM | 5.3 | 1.0% | Jun 24, 2022 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information... |
| CVE-2021-38871 | MEDIUM | 5.4 | 0.5% | Jun 24, 2022 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability all... |
| CVE-2021-29865 | MEDIUM | 5.4 | 0.6% | Jun 24, 2022 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action o... |
| CVE-2021-20544 | MEDIUM | 4.3 | 0.5% | Jun 24, 2022 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may... |
| CVE-2021-20543 | MEDIUM | 5.4 | 0.6% | Jun 24, 2022 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTML injection. A remote attacker could inje... |
| CVE-2021-20421 | MEDIUM | 4.3 | 0.5% | Jun 24, 2022 | IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now