2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-30152 | MEDIUM | 4.3 | 1.2% | Apr 9, 2021 | An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki AP... |
| CVE-2021-3482 | MEDIUM | 6.5 | 2.3% | Apr 8, 2021 | A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size pro... |
| CVE-2021-3448 | MEDIUM | 4 | 2.0% | Apr 8, 2021 | A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interf... |
| CVE-2021-3413 | MEDIUM | 6.3 | 0.7% | Apr 8, 2021 | A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was id... |
| CVE-2021-22513 | MEDIUM | 6.5 | 1.2% | Apr 8, 2021 | Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerabili... |
| CVE-2021-22512 | MEDIUM | 6.5 | 0.7% | Apr 8, 2021 | Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The... |
| CVE-2021-22511 | MEDIUM | 6.5 | 0.4% | Apr 8, 2021 | Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The v... |
| CVE-2021-22510 | MEDIUM | 6.1 | 5.0% | Apr 8, 2021 | Reflected XSS vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affec... |
| CVE-2021-29154 | HIGH | 7.8 | 0.9% | Apr 8, 2021 | BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them ... |
| CVE-2021-3146 | HIGH | 7.8 | 0.4% | Apr 8, 2021 | The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges. |
| CVE-2021-22312 | MEDIUM | 6.5 | 0.8% | Apr 8, 2021 | There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerab... |
| CVE-2021-3328 | HIGH | 7.5 | 1.8% | Apr 8, 2021 | An issue was discovered in Aprelium Abyss Web Server X1 2.12.1 and 2.14. A crafted HTTP request can lead to an out-of-bo... |
| CVE-2021-22507 | CRITICAL | 9.8 | 1.7% | Apr 8, 2021 | Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 ... |
| CVE-2021-22115 | MEDIUM | 6.5 | 0.8% | Apr 8, 2021 | Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config... |
| CVE-2021-27945 | MEDIUM | 6.1 | 0.6% | Apr 8, 2021 | The Squirro Insights Engine was affected by a Reflected Cross-Site Scripting (XSS) vulnerability affecting versions 2.0.... |
| CVE-2021-27522 | HIGH | 8.8 | 1.1% | Apr 8, 2021 | Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() ... |
| CVE-2021-30463 | HIGH | 7.8 | 0.5% | Apr 8, 2021 | VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissio... |
| CVE-2021-30462 | HIGH | 7.2 | 1.8% | Apr 8, 2021 | VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not re... |
| CVE-2021-28925 | CRITICAL | 9.8 | 4.2% | Apr 8, 2021 | SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/. |
| CVE-2021-28924 | MEDIUM | 6.1 | 9.2% | Apr 8, 2021 | Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page. |
| CVE-2021-20480 | MEDIUM | 6.5 | 1.3% | Apr 8, 2021 | IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a spe... |
| CVE-2021-30114 | MEDIUM | 6.5 | 0.7% | Apr 8, 2021 | Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create ... |
| CVE-2021-30113 | MEDIUM | 6.1 | 0.9% | Apr 8, 2021 | A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attac... |
| CVE-2021-30112 | MEDIUM | 6.5 | 0.7% | Apr 8, 2021 | Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create ... |
| CVE-2021-30111 | MEDIUM | 5.4 | 0.7% | Apr 8, 2021 | A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An ... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now