2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-39753MEDIUM5.5In DomainVerificationService, there is a possible way to access app domain verification information due to a missing per...
CVE-2021-39751MEDIUM5.5In Settings, there is a possible way to read Bluetooth device names without proper permissions due to a missing permissi...
CVE-2021-39748MEDIUM5.5In InputMethodEditor, there is a possible way to access some files accessible to Settings due to an unsafe PendingIntent...
CVE-2021-39747MEDIUM5.5In Settings Provider, there is a possible way to list values of non-readable global settings due to a permissions bypass...
CVE-2021-39745MEDIUM5.5In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due...
CVE-2021-39744MEDIUM5.5In DevicePolicyManager, there is a possible way to determine whether an app is installed, without query permissions, due...
CVE-2021-39742MEDIUM5.5In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing permission check. This could l...
CVE-2021-39740MEDIUM5.5In Messaging, there is a possible way to bypass attachment restrictions due to improper input validation. This could lea...
CVE-2021-41594MEDIUM6.5In RSA Archer 6.9.SP1 P3, if some application functions are precluded by the Administrator, this can be bypassed by inte...
CVE-2021-42970MEDIUM6.1Cross Site Scripting (XSS) vulnerability exists in cxuucms v3 via the imgurl of /feedback/post/ content parameter.
CVE-2021-43701MEDIUM6.5CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/articl...
CVE-2021-22572MEDIUM5.5On unix-like systems, the system temporary directory is shared between all users on that system. The root cause is File....
CVE-2021-45866MEDIUM5.4A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Student Attendance Management System 1.0 via ...
CVE-2021-43105MEDIUM4.3A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific maliciou...
CVE-2021-43099MEDIUM4.9An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction....
CVE-2021-4191MEDIUM5.3An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2. Priv...
CVE-2021-39876MEDIUM4.3In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of p...
CVE-2021-25071MEDIUM6.1The WordPress plugin through 2.0.1 does not sanitise and escape the translation parameter before outputting it back in a...
CVE-2021-25012MEDIUM6.1The Pz-LinkCard WordPress plugin through 2.4.4.4 does not sanitise and escape multiple parameters before outputting them...
CVE-2021-24978MEDIUM5.3The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related post type named 'map' and...
CVE-2021-24746MEDIUM6.1The Social Sharing Plugin WordPress plugin before 3.3.40 does not escape the viewed post URL before outputting it back i...
CVE-2021-43721MEDIUM6.1Leanote 2.7.0 is vulnerable to Cross Site Scripting (XSS) in the markdown type note. This leads to remote code execution...
CVE-2021-43725MEDIUM6.1There is a Cross Site Scripting (XSS) vulnerability in SpotPage_login.php of Spotweb 1.5.1 and below, which allows remot...
CVE-2021-46434MEDIUM5.3EMQ X Dashboard V3.0.0 is affected by username enumeration in the "/api /v3/auth" interface. When a user login, the appl...
CVE-2021-45491MEDIUM6.53CX System through 2022-03-17 stores cleartext passwords in a database.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now