2021 CVE Vulnerabilities

23,468 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-30152MEDIUM4.3An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki AP...
CVE-2021-3482MEDIUM6.5A flaw was found in Exiv2 in versions before and including 0.27.4-RC1. Improper input validation of the rawData.size pro...
CVE-2021-3448MEDIUM4A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interf...
CVE-2021-3413MEDIUM6.3A flaw was found in Red Hat Satellite in tfm-rubygem-foreman_azure_rm in versions before 2.2.0. A credential leak was id...
CVE-2021-22513MEDIUM6.5Missing Authorization vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerabili...
CVE-2021-22512MEDIUM6.5Cross-Site Request Forgery (CSRF) vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The...
CVE-2021-22511MEDIUM6.5Improper Certificate Validation vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The v...
CVE-2021-22510MEDIUM6.1Reflected XSS vulnerability in Micro Focus Application Automation Tools Plugin - Jenkins plugin. The vulnerability affec...
CVE-2021-29154HIGH7.8BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them ...
CVE-2021-3146HIGH7.8The Dolby Audio X2 (DAX2) API service before 0.8.8.90 on Windows allows local users to gain privileges.
CVE-2021-22312MEDIUM6.5There is a memory leak vulnerability in some Huawei products. An authenticated remote attacker may exploit this vulnerab...
CVE-2021-3328HIGH7.5An issue was discovered in Aprelium Abyss Web Server X1 2.12.1 and 2.14. A crafted HTTP request can lead to an out-of-bo...
CVE-2021-22507CRITICAL9.8Authentication bypass vulnerability in Micro Focus Operations Bridge Manager affects versions 2019.05, 2019.11, 2020.05 ...
CVE-2021-22115MEDIUM6.5Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config...
CVE-2021-27945MEDIUM6.1The Squirro Insights Engine was affected by a Reflected Cross-Site Scripting (XSS) vulnerability affecting versions 2.0....
CVE-2021-27522HIGH8.8Learnsite 1.2.5.0 contains a remote privilege escalation vulnerability in /Manager/index.aspx through the JudgIsAdmin() ...
CVE-2021-30463HIGH7.8VestaCP through 0.9.8-24 allows attackers to gain privileges by creating symlinks to files for which they lack permissio...
CVE-2021-30462HIGH7.2VestaCP through 0.9.8-24 allows the admin user to escalate privileges to root because the Sudo configuration does not re...
CVE-2021-28925CRITICAL9.8SQL injection vulnerability in Nagios Network Analyzer before 2.4.3 via the o[col] parameter to api/checks/read/.
CVE-2021-28924MEDIUM6.1Self Authenticated XSS in Nagios Network Analyzer before 2.4.2 via the nagiosna/groups/queries page.
CVE-2021-20480MEDIUM6.5IBM WebSphere Application Server 7.0, 8.0, and 8.5 is vulnerable to server-side request forgery (SSRF). By sending a spe...
CVE-2021-30114MEDIUM6.5Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create ...
CVE-2021-30113MEDIUM6.1A blind XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in event name and description fields. An attac...
CVE-2021-30112MEDIUM6.5Web-School ERP V 5.0 contains a cross-site request forgery (CSRF) vulnerability that allows a remote attacker to create ...
CVE-2021-30111MEDIUM5.4A stored XSS vulnerability exists in Web-School ERP V 5.0 via (Add Events) in the event name and description fields. An ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now