2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-35229MEDIUM6.1Cross-site scripting vulnerability is present in Database Performance Monitor 2022.1.7779 and previous versions when usi...
CVE-2021-23055MEDIUM6.5On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ing...
CVE-2021-41162MEDIUM6.1Combodo iTop is a web based IT Service Management tool. In 3.0.0 beta releases prior to beta6 the `ajax.render.php?opera...
CVE-2021-41161MEDIUM6.1Combodo iTop is a web based IT Service Management tool. In versions prior to 3.0.0-beta6 the export CSV page don't prope...
CVE-2021-43990MEDIUM5.3The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload...
CVE-2021-43988MEDIUM5.9The affected product is vulnerable to a network-based attack by threat actors utilizing crafted naming conventions of fi...
CVE-2021-43933MEDIUM5.9The affected product is vulnerable to a network-based attack by threat actors sending unimpeded requests to the receivin...
CVE-2021-38483MEDIUM5.7The affected product is vulnerable to misconfigured binaries, allowing users on the target PC with SYSTEM level privileg...
CVE-2021-23283MEDIUM5.4Eaton Intelligent Power Protector (IPP) prior to version 1.69 is vulnerable to stored Cross Site Scripting. The vulnerab...
CVE-2021-39078MEDIUM4.4IBM Security Guardium 10.5 stores user credentials in plain clear text which can be read by a local privileged user. IBM...
CVE-2021-39072MEDIUM5.9IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information, caused by the failure to prope...
CVE-2021-39033MEDIUM6.5IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote at...
CVE-2021-43129MEDIUM6.5A bypass exists for Desire2Learn/D2L Brightspace’s “Disable Right Click” option in the quizzing feature, which allows a ...
CVE-2021-41570MEDIUM5.4Veritas NetBackup OpsCenter Analytics 9.1 allows XSS via the NetBackup Master Server Name, Display Name, NetBackup User ...
CVE-2021-25120MEDIUM6.1The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX ...
CVE-2021-42782MEDIUM5.3Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash p...
CVE-2021-42781MEDIUM5.3Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash...
CVE-2021-42780MEDIUM5.3A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash p...
CVE-2021-42779MEDIUM5.3A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
CVE-2021-42778MEDIUM5.3A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
CVE-2021-3681MEDIUM5.5A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directo...
CVE-2021-3652MEDIUM6.5A flaw was found in 389-ds-base. If an asterisk is imported as password hashes, either accidentally or maliciously, then...
CVE-2021-3503MEDIUM4.3A flaw was found in Wildfly where insufficient RBAC restrictions may lead to expose metrics data. The highest threat fro...
CVE-2021-23285MEDIUM4.8Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vuln...
CVE-2021-23284MEDIUM4.8Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all prior versions are vuln...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now