2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-44213MEDIUM6.1OX App Suite through 7.10.5 allows XSS via uuencoding in a multipart/alternative message.
CVE-2021-44212MEDIUM6.1OX App Suite through 7.10.5 allows XSS via a trailing control character such as the SCRIPT\t substring.
CVE-2021-44211MEDIUM5.4OX App Suite through 7.10.5 allows XSS via the class attribute of an element in an HTML e-mail signature.
CVE-2021-44210MEDIUM6.1OX App Suite through 7.10.5 allows XSS via NIFF (Notation Interchange File Format) data.
CVE-2021-44209MEDIUM6.1OX App Suite through 7.10.5 allows XSS via an HTML 5 element such as AUDIO.
CVE-2021-44208MEDIUM6.1OX App Suite through 7.10.5 allows XSS via an unknown system message in Chat.
CVE-2021-26598MEDIUM5.3ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated atta...
CVE-2021-40906MEDIUM6.1CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in...
CVE-2021-4203MEDIUM6.8A use-after-free read flaw was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race w...
CVE-2021-4147MEDIUM6.5A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on t...
CVE-2021-44768MEDIUM5.5Delta Electronics CNCSoft (Version 1.01.30) and prior) is vulnerable to an out-of-bounds read while processing a specifi...
CVE-2021-3941MEDIUM6.5In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x -...
CVE-2021-3933MEDIUM5.5An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could caus...
CVE-2021-3582MEDIUM6.5A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device. The issue occurs while handling a "PVRD...
CVE-2021-22100MEDIUM5.3In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker...
CVE-2021-20323MEDIUM6.1A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
CVE-2021-20290MEDIUM6.1An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart-proxy allows foreman cli...
CVE-2021-46426MEDIUM6.1phpIPAM 1.4.4 allows Reflected XSS and CSRF via app/admin/subnets/find_free_section_subnets.php of the subnets functiona...
CVE-2021-44751MEDIUM5.3A vulnerability affecting F-Secure SAFE browser was discovered. A maliciously crafted website attached with USSD code in...
CVE-2021-39491MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in Yogesh Ojha reNgine v1.0 via the Scan Engine name file in the Scan ...
CVE-2021-43659MEDIUM5.4In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, wh...
CVE-2021-28275MEDIUM5.5A Denial of Service vulnerability exists in jhead 3.04 and 3.05 due to a wild address read in the Get16u function in exi...
CVE-2021-4219MEDIUM5.5A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of...
CVE-2021-4180MEDIUM4.3An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or ...
CVE-2021-4150MEDIUM5.5A use-after-free flaw was found in the add_partition in block/partitions/core.c in the Linux kernel. A local attacker wi...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now