2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-24810MEDIUM4.8The WP Event Manager WordPress plugin before 3.1.23 does not escape some of its Field Editor settings when outputting th...
CVE-2021-44748MEDIUM6.1A vulnerability affecting F-Secure SAFE browser was discovered whereby browsers loads images automatically this vulnerab...
CVE-2021-46353MEDIUM5.3An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacke...
CVE-2021-43590MEDIUM6Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password st...
CVE-2021-3428MEDIUM5.5A flaw was found in the Linux kernel. A denial of service problem is identified if an extent tree is corrupted in a craf...
CVE-2021-20303MEDIUM6.1A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able to submit a crafted fil...
CVE-2021-20302MEDIUM5.5A flaw was found in OpenEXR's TiledInputFile functionality. This flaw allows an attacker who can submit a crafted single...
CVE-2021-20300MEDIUM5.5A flaw was found in OpenEXR's hufUncompress functionality in OpenEXR/IlmImf/ImfHuf.cpp. This flaw allows an attacker who...
CVE-2021-46382MEDIUM6.1Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session h...
CVE-2021-46379MEDIUM6.1DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust...
CVE-2021-3744MEDIUM5.5A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, ...
CVE-2021-44321MEDIUM5Mini-Inventory-and-Sales-Management-System is affected by Cross Site Request Forgery (CSRF), where an attacker can updat...
CVE-2021-43393MEDIUM6.2STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to abuse signature verification. ...
CVE-2021-43392MEDIUM6.2STMicroelectronics STSAFE-J 1.1.4, J-SAFE3 1.2.5, and J-SIGN sometimes allow attackers to obtain information on cryptogr...
CVE-2021-3638MEDIUM6.5An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_bl...
CVE-2021-4002MEDIUM4.4A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memor...
CVE-2021-3620MEDIUM5.5A flaw was found in Ansible Engine's ansible-connection module, where sensitive information such as the Ansible user cre...
CVE-2021-3602MEDIUM5.5An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes ...
CVE-2021-43774MEDIUM4.9A risky-algorithm issue was discovered on Fujifilm DocuCentre-VI C4471 1.8 devices. An attacker that obtained access to ...
CVE-2021-40637MEDIUM6.1OS4ED openSIS 8.0 is affected by cross-site scripting (XSS) in EmailCheckOthers.php. An attacker can inject JavaScript c...
CVE-2021-38269MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Gogo Shell module in Liferay Portal 7.1.0 through 7.3.6 and 7.4.0, and L...
CVE-2021-38267MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Blogs module's edit blog entry page in Liferay Portal 7.3.2 through 7.3....
CVE-2021-38265MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Asset module in Liferay Portal 7.3.4 through 7.3.6 allow remote attacker...
CVE-2021-38264MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Frontend Taglib module in Liferay Portal 7.4.0 and 7.4.1 allows remote a...
CVE-2021-38263MEDIUM6.1Cross-site scripting (XSS) vulnerability in the Server module's script console in Liferay Portal 7.3.2 and earlier, and ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now