2021 CVE Vulnerabilities

23,445 CVEs published in 2021.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2021-3947MEDIUM5.5A stack-buffer-overflow was found in QEMU in the NVME component. The flaw lies in nvme_changed_nslist() where a maliciou...
CVE-2021-3930MEDIUM6.5An off-by-one error was found in the SCSI device emulation in QEMU. It could occur while processing MODE SELECT commands...
CVE-2021-39026MEDIUM5.9IBM Guardium Data Encryption (GDE) 5.0.0.2 and 5.0.0.3 could allow a remote attacker to obtain sensitive information, ca...
CVE-2021-30650MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in the Symantec Layer7 API Management OAuth Toolkit (OTK) allows a ...
CVE-2021-20321MEDIUM4.7A race condition accessing file object in the Linux kernel OverlayFS subsystem was found in the way users do rename in s...
CVE-2021-20320MEDIUM5.5A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a l...
CVE-2021-20315MEDIUM6.1A locking protection bypass flaw was found in some versions of gnome-shell as shipped within CentOS Stream 8, when the "...
CVE-2021-46372MEDIUM5.4Scoold 1.47.2 is a Q&A/knowledge base platform written in Java. When writing a Q&A, the markdown editor is vulnerable to...
CVE-2021-46108MEDIUM5.4D-Link DSL-2730E CT-20131125 devices allow XSS via the username parameter to the password page in the maintenance config...
CVE-2021-3155MEDIUM5.5snapd 2.54.2 and earlier created ~/snap directories in user home directories without specifying owner-only permissions. ...
CVE-2021-3753MEDIUM4.7A race problem was seen in the vt_k_ioctl in drivers/tty/vt/vt_ioctl.c in the Linux kernel, which may cause an out of bo...
CVE-2021-4134MEDIUM4.9The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameteriza...
CVE-2021-3557MEDIUM6.5A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created Servi...
CVE-2021-22041MEDIUM6.7VMware ESXi, Workstation, and Fusion contain a double-fetch vulnerability in the UHCI USB controller. A malicious actor ...
CVE-2021-22040MEDIUM6.7VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious acto...
CVE-2021-21966MEDIUM5.3An information disclosure vulnerability exists in the HTTP Server /ping.html functionality of Texas Instruments CC3200 S...
CVE-2021-46252MEDIUM6.5A Cross-Site Request Forgery (CSRF) in RequirementsBypassPage.php of Scratch Wiki scratch-confirmaccount-v3 allows attac...
CVE-2021-46251MEDIUM6.1A reflected cross-site scripting (XSS) in ScratchOAuth2 before commit 1603f04e44ef67dde6ccffe866d2dca16defb293 allows at...
CVE-2021-46249MEDIUM6.5An authorization bypass exploited by a user-controlled key in SpecificApps REST API in ScratchOAuth2 before commit d856d...
CVE-2021-44960MEDIUM6.5In SVGPP SVG++ library 1.3.0, the XMLDocument::getRoot function in the renderDocument function handled the XMLDocument o...
CVE-2021-46558MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the Add User module of Issabel PBX 20200102 allows attackers to e...
CVE-2021-46557MEDIUM5.4Vicidial 2.14-783a was discovered to contain a cross-site scripting (XSS) vulnerability via the input tabs.
CVE-2021-43948MEDIUM4.3Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated remote attackers to vi...
CVE-2021-43941MEDIUM6.5Affected versions of Atlassian Jira Server and Data Center allow remote attackers to modify several resources (including...
CVE-2021-43953MEDIUM4.3Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers to toggle the Thread C...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now