2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-41849MEDIUM5.5An issue was discovered in Luna Simo PPR1.180610.011/202001031830. It sends the following Personally Identifiable Inform...
CVE-2021-44667MEDIUM6.1A Cross Site Scripting (XSS) vulnerability exists in Nacos 2.0.3 in auth/users via the (1) pageSize and (2) pageNo param...
CVE-2021-33150MEDIUM6.8Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an un...
CVE-2021-32478MEDIUM6.1The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect ...
CVE-2021-32477MEDIUM4.3The last time a user accessed the mobile app is displayed on their profile page, but should be restricted to users with ...
CVE-2021-32475MEDIUM5.4ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10...
CVE-2021-32473MEDIUM5.3It was possible for a student to view their quiz grade before it had been released, using a quiz web service. Moodle 3.1...
CVE-2021-32472MEDIUM4.3Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle ve...
CVE-2021-32009MEDIUM6.1Cross-site Scripting (XSS) vulnerability in firmware section of Secomea GateManager allows logged in user to inject java...
CVE-2021-27416MEDIUM5.4An attacker could exploit this vulnerability in Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versio...
CVE-2021-27414MEDIUM6.1An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management (EAM) versions prior to an...
CVE-2021-26401MEDIUM5.6LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
CVE-2021-26341MEDIUM6.5Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage...
CVE-2021-46708MEDIUM6.1The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the ...
CVE-2021-44585MEDIUM6.1A Cross Site Scripting (XSS) vulnerabilitiy exits in jeecg-boot 3.0 in /jeecg-boot/jmreport/view with a mouseover event.
CVE-2021-41233MEDIUM5.3Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with t...
CVE-2021-39025MEDIUM5.3IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 could disclose internal IP address information when the web backe...
CVE-2021-38910MEDIUM5.3IBM DataPower Gateway V10CD, 10.0.1, and 2108.4.1 could allow a remote attacker to bypass security restrictions, caused ...
CVE-2021-4095MEDIUM5.5A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU...
CVE-2021-4023MEDIUM5.5A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic...
CVE-2021-44421MEDIUM5.5The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a confused deputy that al...
CVE-2021-44269MEDIUM5.5An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPack...
CVE-2021-44216MEDIUM5.5Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unautho...
CVE-2021-44215MEDIUM5.5Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users ...
CVE-2021-43969MEDIUM6.5The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Intera...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now