2021 CVE Vulnerabilities
23,468 CVEs published in 2021.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22696 | HIGH | 7.5 | 6.6% | Apr 2, 2021 | CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: ... |
| CVE-2021-30000 | CRITICAL | 9.8 | 2.1% | Apr 2, 2021 | An issue was discovered in LATRIX 0.6.0. SQL injection in the txtaccesscode parameter of inandout.php leads to informati... |
| CVE-2021-30004 | MEDIUM | 5.3 | 1.7% | Apr 2, 2021 | In wpa_supplicant and hostapd 2.9, forging attacks may occur because AlgorithmIdentifier parameters are mishandled in tl... |
| CVE-2021-30003 | MEDIUM | 4.8 | 0.6% | Apr 2, 2021 | An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface vi... |
| CVE-2021-30002 | MEDIUM | 6.2 | 0.4% | Apr 2, 2021 | An issue was discovered in the Linux kernel before 5.11.3 when a webcam device exists. video_usercopy in drivers/media/v... |
| CVE-2021-23925 | MEDIUM | 6.1 | 0.6% | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entr... |
| CVE-2021-23924 | HIGH | 7.5 | 1.0% | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic... |
| CVE-2021-23923 | HIGH | 8.1 | 0.8% | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users. |
| CVE-2021-23922 | MEDIUM | 5.4 | 1.1% | Apr 1, 2021 | An issue was discovered in Devolutions Remote Desktop Manager before 2020.2.12. There is a cross-site scripting (XSS) vu... |
| CVE-2021-23921 | CRITICAL | 9.1 | 1.0% | Apr 1, 2021 | An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry eleme... |
| CVE-2021-21421 | MEDIUM | 6.5 | 1.1% | Apr 1, 2021 | node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client err... |
| CVE-2021-21420 | HIGH | 7.8 | 0.6% | Apr 1, 2021 | vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists ... |
| CVE-2021-21416 | LOW | 2.6 | 0.4% | Apr 1, 2021 | django-registration is a user registration package for Django. The django-registration package provides tools for implem... |
| CVE-2021-28047 | MEDIUM | 5.4 | 1.1% | Apr 1, 2021 | Cross-Site Scripting (XSS) in Administrative Reports in Devolutions Remote Desktop Manager before 2021.1 allows remote a... |
| CVE-2021-29421 | HIGH | 7.5 | 1.7% | Apr 1, 2021 | models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries. |
| CVE-2021-28970 | MEDIUM | 6.5 | 1.3% | Apr 1, 2021 | eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL ... |
| CVE-2021-28969 | MEDIUM | 6.5 | 1.3% | Apr 1, 2021 | eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the ... |
| CVE-2021-27653 | MEDIUM | 4.9 | 1.1% | Apr 1, 2021 | Misconfiguration of the Pega Chat Access Group portal in Pega platform 7.4.0 - 8.5.x could lead to unintended data expos... |
| CVE-2021-26718 | MEDIUM | 5.5 | 0.2% | Apr 1, 2021 | KIS for macOS in some use cases was vulnerable to AV bypass that potentially allowed an attacker to disable anti-virus p... |
| CVE-2021-26581 | MEDIUM | 6.5 | 0.8% | Apr 1, 2021 | A potential security vulnerability has been identified in HPE Superdome Flex server. A denial of service attack can be r... |
| CVE-2021-26580 | MEDIUM | 6.1 | 0.6% | Apr 1, 2021 | A potential security vulnerability has been identified in HPE iLO Amplifier Pack. The vulnerability could be remotely ex... |
| CVE-2021-26072 | MEDIUM | 4.3 | 38.8% | Apr 1, 2021 | The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers... |
| CVE-2021-21982 | CRITICAL | 9.1 | 1.4% | Apr 1, 2021 | VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a ... |
| CVE-2021-20078 | CRITICAL | 9.1 | 60.4% | Apr 1, 2021 | Manage Engine OpManager builds below 125346 are vulnerable to a remote denial of service vulnerability due to a path tra... |
| CVE-2021-3447 | MEDIUM | 5.5 | 0.3% | Apr 1, 2021 | A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged... |
Check if your code is affected by 2021 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now