2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-45721MEDIUM6.1JFrog Artifactory prior to version 7.29.8 and 6.23.38 is vulnerable to Reflected Cross-Site Scripting (XSS) through one ...
CVE-2021-25066MEDIUM4.8The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitize and escape some imported data, allowing hi...
CVE-2021-25056MEDIUM4.8The Ninja Forms Contact Form WordPress plugin before 3.6.10 does not sanitise and escape field labels, allowing high pri...
CVE-2021-37524MEDIUM6.1Cross Site Scripting (XSS) vulnerability in FusionPBX 4.5.26 allows remote unauthenticated users to inject arbitrary web...
CVE-2021-38954MEDIUM4.3IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could disclose sensitiv...
CVE-2021-37791MEDIUM4.9MyAdmin v1.0 is affected by an incorrect access control vulnerability in viewing personal center in /api/user/userData?u...
CVE-2021-39074MEDIUM6.1IBM Security Guardium 11.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary Jav...
CVE-2021-40642MEDIUM4.3Textpattern CMS v4.8.7 and older vulnerability exists through Sensitive Cookie in HTTPS Session Without 'Secure' Attribu...
CVE-2021-41559MEDIUM6.5Silverstripe silverstripe/framework 4.8.1 has a quadratic blowup in Convert::xml2array() that enables a remote attack vi...
CVE-2021-3779MEDIUM6.5A malicious MySQL server can request local file content from a client using ruby-mysql prior to version 2.10.0 without e...
CVE-2021-40944MEDIUM5.5In GPAC MP4Box 1.1.0, there is a Null pointer reference in the function gf_filter_pid_get_packet function in src/filter_...
CVE-2021-40943MEDIUM5.5In Bento4 1.6.0-638, there is a null pointer reference in the function AP4_DescriptorListInspector::Action function in A...
CVE-2021-40609MEDIUM5.5The GetHintFormat function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box ...
CVE-2021-40608MEDIUM5.5The gf_hinter_track_finalize function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in ...
CVE-2021-40607MEDIUM5.5The schm_box_size function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4Box ...
CVE-2021-40606MEDIUM5.5The gf_bs_write_data function in GPAC 1.0.1 allows attackers to cause a denial of service via a crafted file in the MP4B...
CVE-2021-40942MEDIUM5.5In GPAC MP4Box v1.1.0, there is a heap-buffer-overflow in the function filter_parse_dyn_args function in filter_core/fil...
CVE-2021-42056MEDIUM6.7Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock ...
CVE-2021-39408MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in Online Student Rate System 1.0 via the page parameter on the index.ph...
CVE-2021-38879MEDIUM5.3IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information...
CVE-2021-38871MEDIUM5.4IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability all...
CVE-2021-29865MEDIUM5.4IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to hijack the clicking action o...
CVE-2021-20544MEDIUM4.3IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may...
CVE-2021-20543MEDIUM5.4IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTML injection. A remote attacker could inje...
CVE-2021-20421MEDIUM4.3IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now