2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-37504MEDIUM6.1A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers t...
CVE-2021-37103MEDIUM5.5There is an improper permission management vulnerability in the Wallet apps. Successful exploitation of this vulnerabili...
CVE-2021-22479MEDIUM5.5The interface of a certain HarmonyOS module has an invalid address access vulnerability. Successful exploitation of this...
CVE-2021-22478MEDIUM5.5The interface of a certain HarmonyOS module has a UAF vulnerability. Successful exploitation of this vulnerability may l...
CVE-2021-22441MEDIUM5.5Some Huawei products have an integer overflow vulnerability. Successful exploitation of this vulnerability may lead to k...
CVE-2021-38993MEDIUM5.5IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the smbcd daem...
CVE-2021-45229MEDIUM6.1It was discovered that the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argume...
CVE-2021-34361MEDIUM6.1A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, t...
CVE-2021-34359MEDIUM5.4A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Proxy Server. If exploited, t...
CVE-2021-43745MEDIUM5.5A Denial of Service vulnerabilty exists in Trilium Notes 0.48.6 in the setupPage function
CVE-2021-29217MEDIUM6.1A remote URL redirection vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE has ...
CVE-2021-29216MEDIUM6.1A remote cross-site scripting vulnerability was discovered in HPE OneView Global Dashboard version(s): Prior to 2.5. HPE...
CVE-2021-44665MEDIUM6.5A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via...
CVE-2021-44662MEDIUM6.1A Site Scripting (XSS) vulnerability exists in the Xerte Project Xerte through 3.8.4 via the link parameter in print.php...
CVE-2021-44533MEDIUM5.3Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly....
CVE-2021-44532MEDIUM5.3Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It u...
CVE-2021-3700MEDIUM6.4A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in us...
CVE-2021-3608MEDIUM6A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue oc...
CVE-2021-3607MEDIUM6An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0....
CVE-2021-3596MEDIUM6.5A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg....
CVE-2021-39038MEDIUM5.4IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 22.0.0.2 could allow ...
CVE-2021-38995MEDIUM5.5IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel...
CVE-2021-38994MEDIUM5.5IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel...
CVE-2021-44608MEDIUM5.4Multiple Cross Site Scripting (XSS) vulnerabilities exists in bloofoxCMS 0.5.2.1 - 0.5.1 via the (1) file parameter and ...
CVE-2021-44607MEDIUM5.4A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now